CVE-2019-16779
published 2019-12-16CVE-2019-16779: In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would…
PriorityP430medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.40%
69.4th percentile
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content from the previous response. The race condition window appears to be short, and it would be difficult to purposefully exploit this.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | ruby-excon | < ruby-excon 0.60.0-2 (bookworm) | ruby-excon 0.60.0-2 (bookworm) |
| excon | excon | < 0.71.0 | 0.71.0 |
| excon | excon | >= 0 < 0.71.0 | 0.71.0 |
| excon_project | excon | < 0.71.0 | 0.71.0 |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
In RubyGem excon, interrupted Persistent Connections May Leak Response Data
osv·2019-12-16
CVE-2019-16779 [MEDIUM] In RubyGem excon, interrupted Persistent Connections May Leak Response Data
In RubyGem excon, interrupted Persistent Connections May Leak Response Data
### Impact
There was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content from the previous response. The race condition window appears to be short, and it would be difficult to purposefully exploit this.
### Patches
The problem has been patched in 0.71.0, users should upgrade to this or a newer version (if one exists).
### Workarounds
Users can workaround the problem by disabling persistent connections, though this may cause performance implications.
### References
See the [patch](https://github.com/excon/excon/commit/ccb57d7a422f020dc74f1de4e8fb505ab46d8a29
OSV
CVE-2019-16779: In RubyGem excon before 0
osv·2019-12-16·CVSS 5.9
CVE-2019-16779 [MEDIUM] CVE-2019-16779: In RubyGem excon before 0
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content from the previous response. The race condition window appears to be short, and it would be difficult to purposefully exploit this.
GHSA
In RubyGem excon, interrupted Persistent Connections May Leak Response Data
ghsa·2019-12-16
CVE-2019-16779 [MEDIUM] CWE-362 In RubyGem excon, interrupted Persistent Connections May Leak Response Data
In RubyGem excon, interrupted Persistent Connections May Leak Response Data
### Impact
There was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content from the previous response. The race condition window appears to be short, and it would be difficult to purposefully exploit this.
### Patches
The problem has been patched in 0.71.0, users should upgrade to this or a newer version (if one exists).
### Workarounds
Users can workaround the problem by disabling persistent connections, though this may cause performance implications.
### References
See the [patch](https://github.com/excon/excon/commit/ccb57d7a422f020dc74f1de4e8fb505ab46d8a29
Debian
CVE-2019-16779: ruby-excon - In RubyGem excon before 0.71.0, there was a race condition around persistent con...
vendor_debian·2019·CVSS 5.8
CVE-2019-16779 [MEDIUM] CVE-2019-16779: ruby-excon - In RubyGem excon before 0.71.0, there was a race condition around persistent con...
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content from the previous response. The race condition window appears to be short, and it would be difficult to purposefully exploit this.
Scope: local
bookworm: resolved (fixed in 0.60.0-2)
bullseye: resolved (fixed in 0.60.0-2)
forky: resolved (fixed in 0.60.0-2)
sid: resolved (fixed in 0.60.0-2)
trixie: resolved (fixed in 0.60.0-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00062.htmlhttps://github.com/excon/excon/commit/ccb57d7a422f020dc74f1de4e8fb505ab46d8a29https://github.com/excon/excon/security/advisories/GHSA-q58g-455p-8vw9https://lists.debian.org/debian-lts-announce/2020/01/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00062.htmlhttps://github.com/excon/excon/commit/ccb57d7a422f020dc74f1de4e8fb505ab46d8a29https://github.com/excon/excon/security/advisories/GHSA-q58g-455p-8vw9https://lists.debian.org/debian-lts-announce/2020/01/msg00015.html
2019-12-16
Published