Resource exhaustion in Rack - CVE-2018-16470
Published: November 19, 2018 / Updated: November 20, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to resource exhaustion condition in the multipart parser when processing malicious input. A remote attacker can send a custom request, cause the parser to use an excessive amount of CPU resources and cause the service to crash.
Affected software
Opensuse
Fedora
rubygem-rack
How to mitigate CVE-2018-16470
rubygem-rack - addressed in versions 2.0.4-4.fc28, 2.0.4-4.fc29