Wind River Support Network

HomeDefectsLIN1019-3656
Fixed

LIN1019-3656 : Security Advisory - ruby - CVE-2019-16254

Created: Nov 29, 2019    Updated: Dec 15, 2019
Resolved Date: Dec 12, 2019
Found In Version: 10.19.45.1
Fix Version: 10.19.45.2
Severity: Standard
Applicable for: Wind River Linux LTS 19
Component/s: Userspace

Description

Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBrick inserts untrusted input into the response header, an attacker can exploit it to insert a newline character to split a header, and inject malicious content to deceive clients. NOTE: this issue exists because of an incomplete fix for CVE-2017-17742, which addressed the CRLF vector, but did not address an isolated CR or an isolated LF.

CREATE(Triage):(User=admin) [CVE-2019-16254|https://nvd.nist.gov/vuln/detail/CVE-2019-16254]

CVEs


Live chat
Online