Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-2664

Опубликовано: 24 июн. 2008
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.8

Описание

The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allows context-dependent attackers to trigger memory corruption via unspecified vectors related to alloca, a different issue than CVE-2008-2662, CVE-2008-2663, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.

РелизСтатусПримечание
dapper

released

1.8.4-1ubuntu1.5
devel

not-affected

1.8.7.22-1
feisty

released

1.8.5-4ubuntu2.2
gutsy

released

1.8.6.36-1ubuntu3.2
hardy

released

1.8.6.111-2ubuntu1.1
intrepid

not-affected

1.8.7.22-1
jaunty

not-affected

1.8.7.22-1
karmic

not-affected

1.8.7.22-1
lucid

not-affected

1.8.7.22-1
maverick

not-affected

1.8.7.22-1

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

pulled 2010-07-27
feisty

ignored

end of life, was needed
gutsy

ignored

end of life, was needed
hardy

ignored

end of life
intrepid

released

1.9.0.2-1ubuntu1
jaunty

released

1.9.0.2-1ubuntu1
karmic

released

1.9.0.2-1ubuntu1
lucid

released

1.9.0.2-1ubuntu1
maverick

DNE

pulled 2010-07-27

Показывать по

EPSS

Процентиль: 90%
0.0535
Низкий

7.8 High

CVSS2

Связанные уязвимости

redhat
около 17 лет назад

The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allows context-dependent attackers to trigger memory corruption via unspecified vectors related to alloca, a different issue than CVE-2008-2662, CVE-2008-2663, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.

nvd
почти 17 лет назад

The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allows context-dependent attackers to trigger memory corruption via unspecified vectors related to alloca, a different issue than CVE-2008-2662, CVE-2008-2663, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.

debian
почти 17 лет назад

The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8 ...

github
около 3 лет назад

The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allows context-dependent attackers to trigger memory corruption via unspecified vectors related to alloca, a different issue than CVE-2008-2662, CVE-2008-2663, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.

oracle-oval
почти 17 лет назад

ELSA-2008-0561: ruby security update (MODERATE)

EPSS

Процентиль: 90%
0.0535
Низкий

7.8 High

CVSS2