SUSE-SU-2025:03466-1
Dashboard / Vulnerabilities / SUSE-SU-2025:03466-1
SUSE-SU-2025:03466-1
Summary: Security update for rubygem-puma
Details: This update for rubygem-puma fixes the following issues: Update to version 5.6.9. - CVE-2024-45614: improper header normalization allows for clients to clobber proxy set headers, which can lead to information leaks (bsc#1230848, fixed in an earlier update). - CVE-2024-21647: unbounded resource consumption due to invalid parsing of chunked encoding in HTTP/1.1 can lead to denial-of-service attacks (bsc#1218638, fixed in an earlier update) - CVE-2023-40175: incorrect behavior when parsing chunked transfer encoding bodies and zero-length Content-Length headers can lead to HTTP request smuggling attacks (bsc#1214425, fixed in an earlier update).
References: https://www.suse.com/support/update/announcement/2025/suse-su-202503466-1/, https://bugzilla.suse.com/1214425, https://bugzilla.suse.com/1218638, https://bugzilla.suse.com/1230848, https://www.suse.com/security/cve/CVE-2023-40175, https://www.suse.com/security/cve/CVE-2024-21647, https://www.suse.com/security/cve/CVE-2024-45614
Affected packages
Package
Name: rubygem-puma
Purl: pkg:rpm/suse/rubygem-puma&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
