Wind River Support Network

HomeDefectsLIN1018-5357
Fixed

LIN1018-5357 : Security Advisory - ruby - CVE-2019-16254

Created: Nov 29, 2019    Updated: Jan 16, 2020
Resolved Date: Dec 15, 2019
Found In Version: 10.18.44.1
Fix Version: 10.18.44.14
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBrick inserts untrusted input into the response header, an attacker can exploit it to insert a newline character to split a header, and inject malicious content to deceive clients. NOTE: this issue exists because of an incomplete fix for CVE-2017-17742, which addressed the CRLF vector, but did not address an isolated CR or an isolated LF.

CREATE(Triage):(User=admin) [CVE-2019-16254|https://nvd.nist.gov/vuln/detail/CVE-2019-16254]

CVEs


Live chat
Online