Moderate severityNVD Advisory· Published Jul 26, 2015· Updated May 6, 2026
CVE-2015-3225
CVE-2015-3225
Description
lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a request with a large parameter depth.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
rackRubyGems | >= 1.5.0, < 1.5.4 | 1.5.4 |
rackRubyGems | >= 1.6.0, < 1.6.2 | 1.6.2 |
rackRubyGems | >= 1.4.0, < 1.4.6 | 1.4.6 |
Affected products
7cpe:2.3:a:rack_project:rack:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:rack_project:rack:*:*:*:*:*:*:*:*range: <=1.5.3
- cpe:2.3:a:rack_project:rack:1.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:rack_project:rack:1.6.1:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
15- github.com/rack/rack/blob/master/HISTORY.mdnvdIssue TrackingPatchVendor AdvisoryWEB
- lists.opensuse.org/opensuse-updates/2015-07/msg00040.htmlnvdThird Party AdvisoryWEB
- lists.opensuse.org/opensuse-updates/2015-07/msg00043.htmlnvdThird Party AdvisoryWEB
- lists.opensuse.org/opensuse-updates/2015-07/msg00044.htmlnvdThird Party AdvisoryWEB
- openwall.com/lists/oss-security/2015/06/16/14nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-rgr4-9jh5-j4j6ghsaADVISORY
- groups.google.com/forum/message/rawnvdMailing ListThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2015-3225ghsaADVISORY
- lists.fedoraproject.org/pipermail/package-announce/2015-August/164173.htmlnvdWEB
- lists.fedoraproject.org/pipermail/package-announce/2015-August/165180.htmlnvdWEB
- rhn.redhat.com/errata/RHSA-2015-2290.htmlnvdWEB
- www.debian.org/security/2015/dsa-3322nvdWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/rack/CVE-2015-3225.ymlghsaWEB
- groups.google.com/forum/ghsaWEB
- www.securityfocus.com/bid/75232nvd
News mentions
0No linked articles in our index yet.