Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-2662

Опубликовано: 24 июн. 2008
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 10

Описание

Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors that trigger memory corruption, a different issue than CVE-2008-2663, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. This CVE description should be regarded as authoritative, although it is likely to change.

РелизСтатусПримечание
dapper

released

1.8.4-1ubuntu1.5
devel

not-affected

1.8.7.22-1
feisty

released

1.8.5-4ubuntu2.2
gutsy

released

1.8.6.36-1ubuntu3.2
hardy

released

1.8.6.111-2ubuntu1.1
intrepid

not-affected

1.8.7.22-1
jaunty

not-affected

1.8.7.22-1
karmic

not-affected

1.8.7.22-1
lucid

not-affected

1.8.7.22-1
maverick

not-affected

1.8.7.22-1

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

pulled 2010-07-27
feisty

ignored

end of life, was needed
gutsy

ignored

end of life, was needed
hardy

ignored

end of life
intrepid

released

1.9.0.2-1ubuntu1
jaunty

released

1.9.0.2-1ubuntu1
karmic

released

1.9.0.2-1ubuntu1
lucid

released

1.9.0.2-1ubuntu1
maverick

DNE

pulled 2010-07-27

Показывать по

EPSS

Процентиль: 83%
0.02133
Низкий

10 Critical

CVSS2

Связанные уязвимости

redhat
около 17 лет назад

Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors that trigger memory corruption, a different issue than CVE-2008-2663, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. This CVE description should be regarded as authoritative, although it is likely to change.

nvd
почти 17 лет назад

Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors that trigger memory corruption, a different issue than CVE-2008-2663, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. This CVE description should be regarded as authoritative, although it is likely to change.

debian
почти 17 лет назад

Multiple integer overflows in the rb_str_buf_append function in Ruby 1 ...

github
около 3 лет назад

Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors that trigger memory corruption, a different issue than CVE-2008-2663, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. This CVE description should be regarded as authoritative, although it is likely to change.

oracle-oval
почти 17 лет назад

ELSA-2008-0561: ruby security update (MODERATE)

EPSS

Процентиль: 83%
0.02133
Низкий

10 Critical

CVSS2