Back

HIGH

rubygem-actionpack: possible object leak and denial of service attack in Action Pack

Published Feb 16, 2016

Description

actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly restrict use of the MIME type cache, which allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP Accept header.

Affected products

Remediation

Red Hat mitigation

Use following code to monkey-patch mime types cache and disable caching. ``` require 'action_dispatch/http/mime_type' Mime.const_set :LOOKUP, Hash.new { |h,k| Mime::Type.new(k) unless k.blank? } ``` Alternatively perform filtering of mime types in the Accept header to allow only known types.

Metrics

References (25)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 16, 2016
Updated Aug 5, 2024
Reserved Dec 16, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 25, 2016
GHSA-FFPV-C4HM-3X6V