Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such situation can lead to a buffer overrun, resulting in a heap memory corruption or an information disclosure from the heap.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2017-09-15 19:29
Updated : 2025-04-20 01:37
NVD link : CVE-2017-0898
Mitre link : CVE-2017-0898
CVE.ORG link : CVE-2017-0898
JSON object : View
Products Affected
ruby-lang
- ruby
CWE
CWE-134
Use of Externally-Controlled Format String