Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-41816

Опубликовано: 06 фев. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This also affects the CGI gem before 0.3.1 for Ruby.

РелизСтатусПримечание
esm-infra/xenial

not-affected

trusty

ignored

end of standard support
upstream

needs-triage

xenial

ignored

end of standard support

Показывать по

РелизСтатусПримечание
bionic

not-affected

esm-infra/bionic

not-affected

trusty

ignored

end of standard support
upstream

needs-triage

xenial

ignored

end of standard support

Показывать по

РелизСтатусПримечание
esm-infra/focal

not-affected

2.7.0-5ubuntu1.6
focal

released

2.7.0-5ubuntu1.6
hirsute

released

2.7.2-4ubuntu1.3
impish

released

2.7.4-1ubuntu3.1
trusty

ignored

end of standard support
upstream

needs-triage

xenial

ignored

end of standard support

Показывать по

РелизСтатусПримечание
devel

released

3.0.2-7ubuntu2
jammy

released

3.0.2-7ubuntu2
trusty

ignored

end of standard support
upstream

needs-triage

xenial

ignored

end of standard support

Показывать по

EPSS

Процентиль: 79%
0.01308
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 3 лет назад

CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This also affects the CGI gem before 0.3.1 for Ruby.

CVSS3: 9.8
nvd
больше 3 лет назад

CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This also affects the CGI gem before 0.3.1 for Ruby.

CVSS3: 9.8
debian
больше 3 лет назад

CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integ ...

CVSS3: 9.8
github
больше 3 лет назад

Buffer overrun in CGI.escape_html

CVSS3: 9.8
fstec
больше 3 лет назад

Уязвимость программного средства cgi gem, вызванная выходом операции за границы буфера в памяти, позволяющая нарушителю выполнить произвольный код в целевой системе

EPSS

Процентиль: 79%
0.01308
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Уязвимость CVE-2021-41816