Описание
Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.
Отчет
This issue did not affect the versions of ruby as shipped with Red Hat Enterprise Linux 5 and 6.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
CloudForms Management Engine 5 | mingw-ruby | Will not fix | ||
CloudForms Management Engine 5 | ruby193-ruby | Will not fix | ||
OpenShift Enterprise 1 | ruby193-ruby | Will not fix | ||
Red Hat Enterprise Linux 5 | ruby | Not affected | ||
Red Hat Enterprise Linux 6 | ruby | Not affected | ||
Red Hat OpenStack Platform 3 | ruby193-ruby | Will not fix | ||
Red Hat OpenStack Platform 4 | ruby193-ruby | Will not fix | ||
Red Hat Satellite 6 | rubygem-rake | Not affected | ||
Red Hat Subscription Asset Manager | ruby193-ruby | Will not fix | ||
Red Hat Enterprise Linux 7 | ruby | Fixed | RHSA-2014:1912 | 26.11.2014 |
Показывать по
Дополнительная информация
Статус:
EPSS
2.6 Low
CVSS2
Связанные уязвимости
Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.
Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.
Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and e ...
Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.
EPSS
2.6 Low
CVSS2