Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10199

Опубликовано: 18 апр. 2018
Источник: debian

Описание

In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_copy(). An attacker that can cause Ruby code to be run can possibly use this to execute arbitrary code.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mrubyfixed1.4.0+20180418+git54905e98-1package
mrubynot-affectedstretchpackage
mrubynot-affectedjessiepackage

Примечания

  • https://github.com/mruby/mruby/issues/4001

  • https://github.com/mruby/mruby/commit/b51b21fc63c9805862322551387d9036f2b63433

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_copy(). An attacker that can cause Ruby code to be run can possibly use this to execute arbitrary code.

CVSS3: 9.8
nvd
почти 8 лет назад

In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_copy(). An attacker that can cause Ruby code to be run can possibly use this to execute arbitrary code.

CVSS3: 9.8
github
больше 3 лет назад

In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_copy(). An attacker that can cause Ruby code to be run can possibly use this to execute arbitrary code.