PT-2023-8901 · Rack+6 · Rack+6

Ooooooo_Q

·

Publicado

2023-01-18

·

Atualizado

2026-03-13

·

CVE-2022-44570

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Rack versions 1.5.0 through 2.0.9.1 Rack versions 2.1.0 through 2.1.4.1 Rack versions 2.2.0 through 2.2.6.1 Rack versions 3.0.0 through 3.0.0.0
Description A denial of service vulnerability in the Range header parsing component of Rack can cause the component to take an unexpected amount of time when processing carefully crafted input, possibly resulting in a denial of service attack vector. Any applications that deal with Range requests, such as streaming applications or applications that serve files, may be impacted.
Recommendations For Rack versions 1.5.0 through 2.0.9.1, update to version 2.0.9.2. For Rack versions 2.1.0 through 2.1.4.1, update to version 2.1.4.2. For Rack versions 2.2.0 through 2.2.6.1, update to version 2.2.6.2. For Rack versions 3.0.0 through 3.0.0.0, update to version 3.0.0.1. As a temporary workaround, consider restricting access to the Range header parsing component until a patch is available. Apply the provided patches for the respective release series if an immediate upgrade is not possible.

Exploit

Correção

DoS

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-02579
CVE-2022-44570
DLA-3298-1
DSA-5530-1
GHSA-65F5-MFPF-VFHJ
MGASA-2023-0106
OESA-2024-2032
OESA-2024-2033
OESA-2024-2034
OESA-2024-2035
OPENSUSE-SU-2023_0276-1
OPENSUSE-SU-2024:12633-1
OPENSUSE-SU-2024:12634-1
OPENSUSE-SU-2024:12974-1
OPENSUSE-SU-2024:13167-1
OPENSUSE-SU-2024:13726-1
OPENSUSE-SU-2024:13727-1
OPENSUSE-SU-2025:14811-1
OPENSUSE-SU-2025:14875-1
OPENSUSE-SU-2026:10286-1
OPENSUSE-SU-2026:10358-1
RHSA-2023:6818
RLSA-2023:6818
SUSE-SU-2023:0276-1
SUSE-SU-2023:0649-1
SUSE-SU-2023_0276-1
USN-5910-1
USN-7036-1

Produtos afetados

Astra Linux
Linuxmint
Rack
Red Os
Rocky Linux
Suse
Ubuntu