Information on source package ruby-rack

Available versions

ReleaseVersion
jessie1.5.2-3+deb8u4
stretch1.6.4-4+deb9u6
stretch (security)1.6.4-4+deb9u2
buster2.0.6-3+deb10u4
bullseye2.1.4-3+deb11u2
bookworm2.2.6.4-1+deb12u1
trixie2.2.7-1.1
sid2.2.7-1.1

Open issues

BugjessiestretchbusterbullseyebookwormtrixiesidDescription
CVE-2024-26146vulnerablefixedfixedfixedfixedfixedfixedRack is a modular Ruby web server interface. Carefully crafted headers ...
CVE-2024-26141vulnerablefixedfixedfixedfixedfixedfixedRack is a modular Ruby web server interface. Carefully crafted Range h ...
CVE-2023-27539vulnerablefixedfixedfixedfixedfixedfixed
CVE-2023-27530vulnerablevulnerable (no DSA, ignored)fixedfixedfixedfixedfixedA DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and ...
CVE-2022-44572vulnerablefixedfixedfixedfixedfixedfixedA denial of service vulnerability in the multipart parsing component o ...
CVE-2022-44571vulnerablefixedfixedfixedfixedfixedfixedThere is a denial of service vulnerability in the Content-Disposition ...
CVE-2022-44570vulnerablefixedfixedfixedfixedfixedfixedA denial of service vulnerability in the Range header parsing componen ...
CVE-2022-30123vulnerablefixedfixedfixedfixedfixedfixedA sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 a ...
CVE-2022-30122vulnerablefixedfixedfixedfixedfixedfixedA possible denial of service vulnerability exists in Rack <2.0.9.1, <2 ...
CVE-2019-16782vulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedfixedThere's a possible information leak / session hijack vulnerability in ...

Resolved issues

BugDescription
CVE-2024-39316Rack is a modular Ruby web server interface. Starting in version 3.1.0 ...
CVE-2024-25126Rack is a modular Ruby web server interface. Carefully crafted content ...
CVE-2020-8184A reliance on cookies without validation/integrity check security vuln ...
CVE-2020-8161A directory traversal vulnerability exists in rack < 2.2.0 that allows ...
CVE-2018-16471There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. ...
CVE-2018-16470There is a possible DoS vulnerability in the multipart parser in Rack ...
CVE-2015-3225lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used ...
CVE-2013-0263Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, ...
CVE-2013-0262rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before ...
CVE-2013-0184Unspecified vulnerability in Rack::Auth::AbstractRequest in Rack 1.1.x ...
CVE-2013-0183multipart/parser.rb in Rack 1.3.x before 1.3.8 and 1.4.x before 1.4.3 ...
CVE-2012-6109lib/rack/multipart.rb in Rack before 1.1.4, 1.2.x before 1.2.6, 1.3.x ...
CVE-2011-5036Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes ...

Security announcements

DSA / DLADescription
DSA-5698-1ruby-rack - security update
DLA-3800-1ruby-rack - security update
ELA-1081-1ruby-rack - security update
DSA-5530-1ruby-rack - security update
ELA-936-1ruby-rack - security update
DLA-3392-1ruby-rack - security update
DLA-3298-1ruby-rack - security update
ELA-785-1ruby-rack - security update
DLA-3095-1ruby-rack - security update
ELA-657-1ruby-rack - security update
ELA-278-1ruby-rack - security update
DLA-2275-1ruby-rack - security update
DLA-2216-1ruby-rack - security update
DLA-1585-1ruby-rack - security update
DSA-3322-1ruby-rack - security update

Search for package or bug name: Reporting problems