Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-15928

Опубликовано: 27 окт. 2017
Источник: debian
EPSS Низкий

Описание

In the Ox gem 2.8.0 for Ruby, the process crashes with a segmentation fault when a crafted input is supplied to parse_obj. NOTE: the vendor has stated "Ox should handle the error more gracefully" but has not confirmed a security implication.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-oxfixed2.8.2-1package
ruby-oxfixed2.1.1-2+deb9u1stretchpackage
ruby-oxfixed2.1.1-2+deb8u1jessiepackage

Примечания

  • https://github.com/ohler55/ox/issues/194

  • https://github.com/ohler55/ox/commit/e4565dbc167f0d38c3f93243d7a4fcfc391cbfc8

EPSS

Процентиль: 64%
0.00459
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

In the Ox gem 2.8.0 for Ruby, the process crashes with a segmentation fault when a crafted input is supplied to parse_obj. NOTE: the vendor has stated "Ox should handle the error more gracefully" but has not confirmed a security implication.

CVSS3: 7.5
nvd
больше 8 лет назад

In the Ox gem 2.8.0 for Ruby, the process crashes with a segmentation fault when a crafted input is supplied to parse_obj. NOTE: the vendor has stated "Ox should handle the error more gracefully" but has not confirmed a security implication.

CVSS3: 7.5
github
около 8 лет назад

Ox gem crashes due to a crafted input

EPSS

Процентиль: 64%
0.00459
Низкий