Security update for rubygem-rack
This update for rubygem-rack fixes the following issues: - CVE-2022-44570: Fixed a potential denial of service when parsing a RFC2183 multipart boundary (bsc#1207597). - CVE-2022-44571: Fixed a potential denial of service when parsing a Range header (bsc#1207599). - CVE-2022-44572: Fixed a potential denial of service when parsing a Content-Disposition header (bsc#1207596).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for rubygem-rack fixes the following issues: - CVE-2022-44570: Fixed a potential denial of service when parsing a RFC2183 multipart boundary (bsc#1207597). - CVE-2022-44571: Fixed a potential denial of service when parsing a Range header (bsc#1207599). - CVE-2022-44572: Fixed a potential denial of service when parsing a Content-Disposition header (bsc#1207596).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1207596
- https://bugzilla.suse.com/1207597
- https://bugzilla.suse.com/1207599
- https://www.suse.com/security/cve/CVE-2022-44570
- https://www.suse.com/security/cve/CVE-2022-44571
- https://www.suse.com/security/cve/CVE-2022-44572
- https://www.suse.com/support/update/announcement/2023/suse-su-20230276-1/