Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-444w-xm89-r2p5

Опубликовано: 07 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_GETUPVAR in the presence of deep scope nesting, resulting in a use-after-free. An attacker that can cause Ruby code to be run can use this to possibly execute arbitrary code.

In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_GETUPVAR in the presence of deep scope nesting, resulting in a use-after-free. An attacker that can cause Ruby code to be run can use this to possibly execute arbitrary code.

EPSS

Процентиль: 79%
0.01293
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_GETUPVAR in the presence of deep scope nesting, resulting in a use-after-free. An attacker that can cause Ruby code to be run can use this to possibly execute arbitrary code.

CVSS3: 9.8
nvd
почти 8 лет назад

In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_GETUPVAR in the presence of deep scope nesting, resulting in a use-after-free. An attacker that can cause Ruby code to be run can use this to possibly execute arbitrary code.

CVSS3: 9.8
debian
почти 8 лет назад

In versions of mruby up to and including 1.4.0, an integer overflow ex ...

EPSS

Процентиль: 79%
0.01293
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-190