Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-12248

Опубликовано: 12 июн. 2018
Источник: debian

Описание

An issue was discovered in mruby 1.4.1. There is a heap-based buffer over-read associated with OP_ENTER because mrbgems/mruby-fiber/src/fiber.c does not extend the stack in cases of many arguments to fiber.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mrubyfixed1.4.1+20180622+git640fca32-1package
mrubyno-dsastretchpackage
mrubyno-dsajessiepackage

Примечания

  • https://github.com/mruby/mruby/commit/778500563a9f7ceba996937dc886bd8cde29b42b

  • https://github.com/mruby/mruby/issues/4038

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

An issue was discovered in mruby 1.4.1. There is a heap-based buffer over-read associated with OP_ENTER because mrbgems/mruby-fiber/src/fiber.c does not extend the stack in cases of many arguments to fiber.

CVSS3: 7.5
nvd
больше 7 лет назад

An issue was discovered in mruby 1.4.1. There is a heap-based buffer over-read associated with OP_ENTER because mrbgems/mruby-fiber/src/fiber.c does not extend the stack in cases of many arguments to fiber.

CVSS3: 7.5
github
больше 3 лет назад

An issue was discovered in mruby 1.4.1. There is a heap-based buffer over-read associated with OP_ENTER because mrbgems/mruby-fiber/src/fiber.c does not extend the stack in cases of many arguments to fiber.