CVE-2021-41816
Summary
| CVE | CVE-2021-41816 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-06 21:15:00 UTC |
| Updated | 2024-01-24 05:15:00 UTC |
| Description | CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This also affects the CGI gem before 0.3.1 for Ruby. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179050 Debian Security Update for ruby2.7 (DSA 5067-1)
- 198635 Ubuntu Security Notification for Ruby Vulnerabilities (USN-5235-1)
- 240720 Red Hat Update for rh-ruby27-ruby security (RHSA-2022:6856)
- 240723 Red Hat Update for rh-ruby30-ruby security (RHSA-2022:6855)
- 282660 Fedora Security Update for ruby (FEDORA-2022-82a9edac27)
- 282661 Fedora Security Update for ruby (FEDORA-2022-8cf0124add)
- 356181 Amazon Linux Security Advisory for ruby : ALASRUBY3.0-2023-003
- 356463 Amazon Linux Security Advisory for ruby : ALAS2RUBY3.0-2023-003
- 500617 Alpine Linux Security Update for ruby
- 502024 Alpine Linux Security Update for ruby
- 504377 Alpine Linux Security Update for ruby
- 690621 Free Berkeley Software Distribution (FreeBSD) Security Update for rubygem-cgi (2c6af5c3-4d36-11ec-a539-0800270512f4)
- 710844 Gentoo Linux Ruby Multiple Vulnerabilities (GLSA 202401-27)
- 904903 Common Base Linux Mariner (CBL-Mariner) Security Update for ruby (12423)