PT-2008-3855 · Ruby+1 · Ruby+1
Tomas Hoger
·
Publicado
2008-07-09
·
Atualizado
2023-02-13
·
CVE-2008-2376
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Ruby versions prior to revision 17756
Description:
The issue is related to an integer overflow in the
rb ary fill function, which can be triggered by calling the Array#fill method with a start argument greater than ARY MAX SIZE. This can lead to a denial of service (crash) or possibly have other unspecified impacts. The problem exists due to an incomplete fix for other closely related integer overflows.Recommendations:
For Ruby versions prior to revision 17756, update to revision 17756 or later to resolve the issue.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat
Ruby