|
Message-ID: <CAMhPm6NxrFTnfdJbT3RkC7rHiUYaXL-EmFREv0Cpued00Dii=g@mail.gmail.com> Date: Mon, 14 Mar 2016 19:37:01 +0000 From: Bart de Water <bart@...nilocode.nl> To: oss-security@...ts.openwall.com Subject: CVE request: DoS vulnerability in Ruby gem Paperclip Hello, I believe there's a denial of service vulnerability in Paperclip version 4.2.2 through 4.3.5: it's possible to cause a DoS by uploading files with a spoofed media type, because it causes megabytes of logging (data from the mime-types gem) to be written. See https://cwe.mitre.org/data/definitions/779.html for more information. It seems to be introduced in this commit https://github.com/thoughtbot/paperclip/commit/9aee4112f36058cd28d5fe4a006d6981bd1eda57 in version 4.2.2 and it's fixed in 4.3.6 (released yesterday) with this pull request: https://github.com/thoughtbot/paperclip/pull/2126 Thanks, Bart de Water
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.