Debian DSA-2783-1 : librack-ruby - several vulnerabilities

medium Nessus Plugin ID 70534

Synopsis

The remote Debian host is missing a security-related update.

Description

Several vulnerabilities were discovered in Rack, a modular Ruby webserver interface. The Common Vulnerabilites and Exposures project identifies the following vulnerabilities :

- CVE-2011-5036 Rack computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

- CVE-2013-0183 A remote attacker could cause a denial of service (memory consumption and out-of-memory error) via a long string in a Multipart HTTP packet.

- CVE-2013-0184 A vulnerability in Rack::Auth::AbstractRequest allows remote attackers to cause a denial of service via unknown vectors.

- CVE-2013-0263 Rack::Session::Cookie allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.

Solution

Upgrade the librack-ruby packages.

For the oldstable distribution (squeeze), these problems have been fixed in version 1.1.0-4+squeeze1.

The stable, testing and unstable distributions do not contain the librack-ruby package. They have already been addressed in version 1.4.1-2.1 of the ruby-rack package.

See Also

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=653963

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=698440

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=700226

https://security-tracker.debian.org/tracker/CVE-2011-5036

https://security-tracker.debian.org/tracker/CVE-2013-0183

https://security-tracker.debian.org/tracker/CVE-2013-0184

https://security-tracker.debian.org/tracker/CVE-2013-0263

https://packages.debian.org/source/squeeze/librack-ruby

https://www.debian.org/security/2013/dsa-2783

Plugin Details

Severity: Medium

ID: 70534

File Name: debian_DSA-2783.nasl

Version: 1.9

Type: local

Agent: unix

Published: 10/22/2013

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 5.1

Temporal Score: 3.8

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:librack-ruby, cpe:/o:debian:debian_linux:6.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 10/21/2013

Reference Information

CVE: CVE-2011-5036, CVE-2013-0183, CVE-2013-0184, CVE-2013-0263

BID: 51197, 57860, 58769

DSA: 2783