Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-9527

Опубликовано: 11 июн. 2017
Источник: debian

Описание

The mark_context_stack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of service (heap-based use-after-free and application crash) or possibly have unspecified other impact via a crafted .rb file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mrubyfixed1.2.0+20170601+git51e0e690-1experimentalpackage
mrubyfixed1.3.0-1package
mrubyno-dsajessiepackage

Примечания

  • https://github.com/mruby/mruby/issues/3486

  • Fixed by: https://github.com/mruby/mruby/commit/5c114c91d4ff31859fcd84cf8bf349b737b90d99

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 8 лет назад

The mark_context_stack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of service (heap-based use-after-free and application crash) or possibly have unspecified other impact via a crafted .rb file.

CVSS3: 7.8
nvd
больше 8 лет назад

The mark_context_stack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of service (heap-based use-after-free and application crash) or possibly have unspecified other impact via a crafted .rb file.

CVSS3: 7.8
github
почти 4 года назад

The mark_context_stack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of service (heap-based use-after-free and application crash) or possibly have unspecified other impact via a crafted .rb file.