Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-2338

Опубликовано: 29 сент. 2022
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS3: 9.8

Описание

An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function heap buffer "head" allocation is made based on tags array length. Specially constructed object passed as element of tags array can increase this array size after mentioned allocation and cause heap overflow.

РелизСтатусПримечание
bionic

not-affected

2.2.4-6build4
devel

not-affected

3.1.0+really3.1.0-1
eoan

not-affected

3.1.0-1build6
esm-apps/bionic

not-affected

2.2.4-6build4
esm-infra-legacy/trusty

DNE

precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

upstream

needs-triage

xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

eoan

DNE

esm-infra-legacy/trusty

DNE

precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

upstream

needs-triage

xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

eoan

DNE

esm-infra-legacy/trusty

DNE

precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

upstream

needs-triage

xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

eoan

DNE

esm-infra-legacy/trusty

DNE

esm-infra/xenial

not-affected

2.3.1-2~ubuntu16.04.14
precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

needs-triage

xenial

not-affected

2.3.1-2~ubuntu16.04.14

Показывать по

РелизСтатусПримечание
bionic

not-affected

2.5.1-1ubuntu1.6
devel

not-affected

2.5.7-1ubuntu3
eoan

not-affected

2.5.5-4ubuntu2.1
esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

2.5.1-1ubuntu1.6
precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

needs-triage

xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

not-affected

2.7.0-4
eoan

DNE

esm-infra-legacy/trusty

DNE

precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

needs-triage

xenial

DNE

Показывать по

EPSS

Процентиль: 94%
0.13462
Средний

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
redhat
больше 3 лет назад

An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function heap buffer "head" allocation is made based on tags array length. Specially constructed object passed as element of tags array can increase this array size after mentioned allocation and cause heap overflow.

CVSS3: 9.8
nvd
больше 3 лет назад

An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function heap buffer "head" allocation is made based on tags array length. Specially constructed object passed as element of tags array can increase this array size after mentioned allocation and cause heap overflow.

CVSS3: 9.8
debian
больше 3 лет назад

An exploitable heap overflow vulnerability exists in the Psych::Emitte ...

CVSS3: 9.8
github
больше 3 лет назад

An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function heap buffer "head" allocation is made based on tags array length. Specially constructed object passed as element of tags array can increase this array size after mentioned allocation and cause heap overflow.

EPSS

Процентиль: 94%
0.13462
Средний

9.8 Critical

CVSS3

Уязвимость CVE-2016-2338