PT-2008-3855 · Ruby+1 · Ruby+1

Tomas Hoger

·

Published

2008-07-09

·

Updated

2023-02-13

·

CVE-2008-2376

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Ruby versions prior to revision 17756
Description: The issue is related to an integer overflow in the rb ary fill function, which can be triggered by calling the Array#fill method with a start argument greater than ARY MAX SIZE. This can lead to a denial of service (crash) or possibly have other unspecified impacts. The problem exists due to an incomplete fix for other closely related integer overflows.
Recommendations: For Ruby versions prior to revision 17756, update to revision 17756 or later to resolve the issue.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2376
DSA-1612-1
DSA-1618-1
RHSA-2008:0561
RHSA-2008:0562
RHSA-2008_0561

Affected Products

Red Hat
Ruby