Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wvmx-3rv2-5jgf

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such situation can lead to a buffer overrun, resulting in a heap memory corruption or an information disclosure from the heap.

Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such situation can lead to a buffer overrun, resulting in a heap memory corruption or an information disclosure from the heap.

EPSS

Процентиль: 74%
0.00846
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-134

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 8 лет назад

Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such situation can lead to a buffer overrun, resulting in a heap memory corruption or an information disclosure from the heap.

CVSS3: 6.5
redhat
около 8 лет назад

Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such situation can lead to a buffer overrun, resulting in a heap memory corruption or an information disclosure from the heap.

CVSS3: 9.1
nvd
около 8 лет назад

Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such situation can lead to a buffer overrun, resulting in a heap memory corruption or an information disclosure from the heap.

CVSS3: 9.1
debian
около 8 лет назад

Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious forma ...

oracle-oval
больше 7 лет назад

ELSA-2018-0378: ruby security update (IMPORTANT)

EPSS

Процентиль: 74%
0.00846
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-134