Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-4975

Опубликовано: 15 нояб. 2014
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5

Описание

Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

lucid

ignored

end of life
precise

not-affected

1.8.7.352-2ubuntu1.4
trusty

DNE

trusty/esm

DNE

upstream

needs-triage

utopic

DNE

vivid

DNE

vivid/stable-phone-overlay

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

lucid

ignored

end of life
precise

DNE

trusty

DNE

trusty/esm

DNE

upstream

needs-triage

utopic

DNE

vivid

DNE

vivid/stable-phone-overlay

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1.9.3.484-2ubuntu1.1]]
lucid

ignored

end of life
precise

released

1.9.3.0-1ubuntu2.9
trusty

released

1.9.3.484-2ubuntu1.1
trusty/esm

DNE

trusty was released [1.9.3.484-2ubuntu1.1]
upstream

needs-triage

utopic

ignored

end of life
vivid

ignored

end of life
vivid/stable-phone-overlay

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [2.0.0.484-1ubuntu2.1]]
lucid

DNE

precise

DNE

trusty

released

2.0.0.484-1ubuntu2.1
trusty/esm

DNE

trusty was released [2.0.0.484-1ubuntu2.1]
upstream

needs-triage

utopic

released

2.0.0.484+really457-3ubuntu1.1
vivid

DNE

vivid/stable-phone-overlay

DNE

Показывать по

РелизСтатусПримечание
devel

released

2.1.2-2ubuntu2
esm-infra-legacy/trusty

DNE

lucid

DNE

precise

DNE

trusty

DNE

trusty/esm

DNE

upstream

needs-triage

utopic

released

2.1.2-2ubuntu1.1
vivid

released

2.1.2-2ubuntu2
vivid/stable-phone-overlay

DNE

Показывать по

EPSS

Процентиль: 86%
0.02908
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
около 11 лет назад

Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.

nvd
почти 11 лет назад

Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.

debian
почти 11 лет назад

Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and e ...

github
больше 3 лет назад

Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.

oracle-oval
больше 9 лет назад

ELSA-2014-1913: ruby193-ruby security update (MODERATE)

EPSS

Процентиль: 86%
0.02908
Низкий

5 Medium

CVSS2