actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly restrict use of the MIME type cache, which allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP Accept header.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2016-02-16T02:00:00

Updated: 2017-09-09T09:57:01

Reserved: 2015-12-16T00:00:00


Link: CVE-2016-0751

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2016-02-16T02:59:05.877

Modified: 2019-08-08T15:43:52.230


Link: CVE-2016-0751

JSON object: View

cve-icon Redhat Information

No data.

CWE