Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-2663

Опубликовано: 24 июн. 2008
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 10

Описание

Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors, a different issue than CVE-2008-2662, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.

РелизСтатусПримечание
dapper

released

1.8.4-1ubuntu1.5
devel

not-affected

1.8.7.22-1
feisty

released

1.8.5-4ubuntu2.2
gutsy

released

1.8.6.36-1ubuntu3.2
hardy

released

1.8.6.111-2ubuntu1.1
intrepid

not-affected

1.8.7.22-1
jaunty

not-affected

1.8.7.22-1
karmic

not-affected

1.8.7.22-1
lucid

not-affected

1.8.7.22-1
maverick

not-affected

1.8.7.22-1

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

pulled 2010-07-27
feisty

ignored

end of life, was needed
gutsy

ignored

end of life, was needed
hardy

ignored

end of life
intrepid

released

1.9.0.2-1ubuntu1
jaunty

released

1.9.0.2-1ubuntu1
karmic

released

1.9.0.2-1ubuntu1
lucid

released

1.9.0.2-1ubuntu1
maverick

DNE

pulled 2010-07-27

Показывать по

EPSS

Процентиль: 88%
0.03878
Низкий

10 Critical

CVSS2

Связанные уязвимости

redhat
около 17 лет назад

Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors, a different issue than CVE-2008-2662, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.

nvd
около 17 лет назад

Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors, a different issue than CVE-2008-2662, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.

debian
около 17 лет назад

Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 ...

github
около 3 лет назад

Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors, a different issue than CVE-2008-2662, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.

oracle-oval
около 17 лет назад

ELSA-2008-0561: ruby security update (MODERATE)

EPSS

Процентиль: 88%
0.03878
Низкий

10 Critical

CVSS2