Hide Forgot
Upstream released [1] Rack 1.4.3 and 1.3.8 to fix a denial of service condition due to a malicious client sending excessively long lines that trigger an out-of-memory error in Rack. This has been fixed in git [2]. [1] https://groups.google.com/forum/#!topic/rack-devel/-MWPHDeGWtI/discussion [2] https://github.com/rack/rack/commit/f95113402b7239f225282806673e1b6424522b18
Created rubygem-rack tracking bugs for this issue Affects: fedora-all [bug 895285]
Created rubygem-rack tracking bugs for this issue Affects: epel-all [bug 771152]
rack-1.3 patch: https://github.com/rack/rack/commit/548b9af2dc0059f4c0c19728624448d84de450ff
rubygem-rack-1.3.0-3.fc16 has been pushed to the Fedora 16 stable repository. If problems still persist, please make note of it in this bug report.
rubygem-rack-1.4.0-4.fc18 has been pushed to the Fedora 18 stable repository. If problems still persist, please make note of it in this bug report.
rubygem-rack-1.4.0-3.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in following products: CloudForms for RHEL 6 Via RHSA-2013:0548 https://rhn.redhat.com/errata/RHSA-2013-0548.html
This issue has been addressed in following products: Red Hat Subscription Asset Manager 1.2 Via RHSA-2013:0544 https://rhn.redhat.com/errata/RHSA-2013-0544.html