PT-2008-3855 · Ruby+1 · Ruby+1

Tomas Hoger

·

Publicado

2008-07-09

·

Atualizado

2023-02-13

·

CVE-2008-2376

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Ruby versions prior to revision 17756
Description: The issue is related to an integer overflow in the rb ary fill function, which can be triggered by calling the Array#fill method with a start argument greater than ARY MAX SIZE. This can lead to a denial of service (crash) or possibly have other unspecified impacts. The problem exists due to an incomplete fix for other closely related integer overflows.
Recommendations: For Ruby versions prior to revision 17756, update to revision 17756 or later to resolve the issue.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-2376
DSA-1612-1
DSA-1618-1
RHSA-2008:0561
RHSA-2008:0562
RHSA-2008_0561

Produtos afetados

Red Hat
Ruby