Описание
Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors, a different issue than CVE-2008-2662, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.
Релиз | Статус | Примечание |
---|---|---|
dapper | released | 1.8.4-1ubuntu1.5 |
devel | not-affected | 1.8.7.22-1 |
feisty | released | 1.8.5-4ubuntu2.2 |
gutsy | released | 1.8.6.36-1ubuntu3.2 |
hardy | released | 1.8.6.111-2ubuntu1.1 |
intrepid | not-affected | 1.8.7.22-1 |
jaunty | not-affected | 1.8.7.22-1 |
karmic | not-affected | 1.8.7.22-1 |
lucid | not-affected | 1.8.7.22-1 |
maverick | not-affected | 1.8.7.22-1 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | ignored | end of life |
devel | DNE | pulled 2010-07-27 |
feisty | ignored | end of life, was needed |
gutsy | ignored | end of life, was needed |
hardy | ignored | end of life |
intrepid | released | 1.9.0.2-1ubuntu1 |
jaunty | released | 1.9.0.2-1ubuntu1 |
karmic | released | 1.9.0.2-1ubuntu1 |
lucid | released | 1.9.0.2-1ubuntu1 |
maverick | DNE | pulled 2010-07-27 |
Показывать по
EPSS
10 Critical
CVSS2
Связанные уязвимости
Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors, a different issue than CVE-2008-2662, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.
Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors, a different issue than CVE-2008-2662, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.
Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 ...
Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors, a different issue than CVE-2008-2662, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.
EPSS
10 Critical
CVSS2