Debian DSA-2783-1 : librack-ruby - several vulnerabilities

Medium Nessus Plugin ID 70534

Synopsis

The remote Debian host is missing a security-related update.

Description

Several vulnerabilities were discovered in Rack, a modular Ruby webserver interface. The Common Vulnerabilites and Exposures project identifies the following vulnerabilities :

- CVE-2011-5036 Rack computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

- CVE-2013-0183 A remote attacker could cause a denial of service (memory consumption and out-of-memory error) via a long string in a Multipart HTTP packet.

- CVE-2013-0184 A vulnerability in Rack::Auth::AbstractRequest allows remote attackers to cause a denial of service via unknown vectors.

- CVE-2013-0263 Rack::Session::Cookie allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.

Solution

Upgrade the librack-ruby packages.

For the oldstable distribution (squeeze), these problems have been fixed in version 1.1.0-4+squeeze1.

The stable, testing and unstable distributions do not contain the librack-ruby package. They have already been addressed in version 1.4.1-2.1 of the ruby-rack package.

See Also

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=653963

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=698440

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=700226

https://security-tracker.debian.org/tracker/CVE-2011-5036

https://security-tracker.debian.org/tracker/CVE-2013-0183

https://security-tracker.debian.org/tracker/CVE-2013-0184

https://security-tracker.debian.org/tracker/CVE-2013-0263

https://packages.debian.org/source/squeeze/librack-ruby

https://www.debian.org/security/2013/dsa-2783

Plugin Details

Severity: Medium

ID: 70534

File Name: debian_DSA-2783.nasl

Version: 1.8

Type: local

Agent: unix

Published: 2013/10/22

Updated: 2020/03/12

Dependencies: 12634

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 5.1

Temporal Score: 3.8

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:librack-ruby, cpe:/o:debian:debian_linux:6.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2013/10/21

Reference Information

CVE: CVE-2011-5036, CVE-2013-0183, CVE-2013-0184, CVE-2013-0263

BID: 51197, 57860, 58769

DSA: 2783