Vulnerability Bulletins

DSA-3322 ruby-rack - security update

   
Affected software Debian
 
Tomek Rabczak from the NCC Group discovered a flaw in thenormalize_params() method in Rack, a modular Ruby webserver interface.A remote attacker can use this flaw via specially crafted requests tocause a `SystemStackError` and potentially cause a denial of servicecondition for the service.

More info:

https://www.debian.org/security/2015/dsa-3322