4.3
CVE-2012-6109
- EPSS 0.83%
- Published 01.03.2013 05:40:16
- Last modified 11.04.2025 00:51:21
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
lib/rack/multipart.rb in Rack before 1.1.4, 1.2.x before 1.2.6, 1.3.x before 1.3.7, and 1.4.x before 1.4.2 uses an incorrect regular expression, which allows remote attackers to cause a denial of service (infinite loop) via a crafted Content-Disposion header.
Data is provided by the National Vulnerability Database (NVD)
Rack Project ≫ Rack Version <= 1.1.3
Rack Project ≫ Rack Version0.1
Rack Project ≫ Rack Version0.2
Rack Project ≫ Rack Version0.3
Rack Project ≫ Rack Version0.4
Rack Project ≫ Rack Version0.9
Rack Project ≫ Rack Version0.9.1
Rack Project ≫ Rack Version1.0.0
Rack Project ≫ Rack Version1.0.1
Rack Project ≫ Rack Version1.1.0
Rack Project ≫ Rack Version1.1.2
Rack Project ≫ Rack Version1.2.0
Rack Project ≫ Rack Version1.2.1
Rack Project ≫ Rack Version1.2.2
Rack Project ≫ Rack Version1.2.3
Rack Project ≫ Rack Version1.2.4
Rack Project ≫ Rack Version1.3.0
Rack Project ≫ Rack Version1.3.1
Rack Project ≫ Rack Version1.3.2
Rack Project ≫ Rack Version1.3.3
Rack Project ≫ Rack Version1.3.4
Rack Project ≫ Rack Version1.3.5
Rack Project ≫ Rack Version1.3.6
Rack Project ≫ Rack Version1.4.0
Rack Project ≫ Rack Version1.4.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.83% | 0.735 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|