Ubuntu Security Notice USN-7036-1

Discussion in 'News Aggregator' started by Packet Storm, 27 Sep 2024.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 7036-1 - It was discovered that Rack was not properly parsing data when processing multipart POST requests. If a user or automated system were tricked into sending a specially crafted multipart POST request to an application using Rack, a remote attacker could possibly use this issue to cause a denial of service. It was discovered that Rack was not properly escaping untrusted data when performing logging operations, which could cause shell escaped sequences to be written to a terminal. If a user or automated system were tricked into sending a specially crafted request to an application using Rack, a remote attacker could possibly use this issue to execute arbitrary code in the machine running the application.

    Continue reading...
     

Share This Page

Loading...