PT-2008-3855 · Ruby+1 · Ruby+1
Tomas Hoger
·
Published
2008-07-09
·
Updated
2023-02-13
·
CVE-2008-2376
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Ruby versions prior to revision 17756
Description:
The issue is related to an integer overflow in the
rb ary fill function, which can be triggered by calling the Array#fill method with a start argument greater than ARY MAX SIZE. This can lead to a denial of service (crash) or possibly have other unspecified impacts. The problem exists due to an incomplete fix for other closely related integer overflows.Recommendations:
For Ruby versions prior to revision 17756, update to revision 17756 or later to resolve the issue.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat
Ruby