Security update for rubygem-rack-1_4
This update for rubygem-rack-1_4 fixes the following issues: - CVE-2024-25126: Fixed a Denial of Service Vulnerability in Rack Content-Type Parsing (bsc#1220239) - CVE-2024-26141: Fixed a Denial of Service Vulnerability in Range request header parsing (bsc#1220242) - CVE-2024-26146: Fixed a Denial of Service vulnerability in Rack headers parsing routine (bsc#1220248)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for rubygem-rack-1_4 fixes the following issues: - CVE-2024-25126: Fixed a Denial of Service Vulnerability in Rack Content-Type Parsing (bsc#1220239) - CVE-2024-26141: Fixed a Denial of Service Vulnerability in Range request header parsing (bsc#1220242) - CVE-2024-26146: Fixed a Denial of Service vulnerability in Rack headers parsing routine (bsc#1220248)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1220239
- https://bugzilla.suse.com/1220242
- https://bugzilla.suse.com/1220248
- https://www.suse.com/security/cve/CVE-2024-25126
- https://www.suse.com/security/cve/CVE-2024-26141
- https://www.suse.com/security/cve/CVE-2024-26146
- https://www.suse.com/support/update/announcement/2024/suse-su-20240946-1/