[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249982

 
 

909

 
 

195748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2022-1895 --- pcs

ID: oval:org.secpod.oval:def:1701082Date: (C)2022-12-08   (M)2024-02-19
Class: PATCHFamily: unix




A denial of service flaw was found in ruby-rack. An attacker crafting multipart POST requests can cause Rack's multipart parser to take much longer than expected, leading to a denial of service. A flaw was found in ruby gem-rack. This flaw allows a malicious actor to craft requests that can cause shell escape sequences to be written to the terminal via rack's `Lint` middleware and `CommonLogger` middleware. This issue can leverage these escape sequences to execute commands in the victim's terminal

Platform:
Amazon Linux 2
Product:
pcs
Reference:
ALAS2-2022-1895
CVE-2022-30122
CVE-2022-30123
CVE    2
CVE-2022-30123
CVE-2022-30122
CPE    2
cpe:/a:pcs:pcs
cpe:/o:amazon:linux:2

© SecPod Technologies