{"api_version":"1","generated_at":"2026-07-23T08:25:18+00:00","cve":"CVE-2011-0188","urls":{"html":"https://cve.report/CVE-2011-0188","api":"https://cve.report/api/cve/CVE-2011-0188.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-0188","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-0188"},"summary":{"title":"CVE-2011-0188","description":"The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Ruby 1.9.2-p136 and earlier, as used on Apple Mac OS X before 10.6.7 and other platforms, does not properly allocate memory, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving creation of a large BigDecimal value within a 64-bit process, related to an \"integer truncation issue.\"","state":"PUBLISHED","assigner":"apple","published_at":"2011-03-23 02:00:06","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-189","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=682332","name":"https://bugzilla.redhat.com/show_bug.cgi?id=682332","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"682332 – (CVE-2011-0188) CVE-2011-0188 ruby: memory corruption in BigDecimal on 64bit platforms","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1025236","name":"http://www.securitytracker.com/id?1025236","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Ruby 64-bit BigDecimal Integer Truncation Flaw Lets Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:098","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:098","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Support / Security / Advisories /  / MDVSA-2011:098 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html","name":"http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"APPLE-SA-2011-03-21-1 Mac OS X v10.6.7 and Security Update 2011-001","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2011-0908.html","name":"http://www.redhat.com/support/errata/RHSA-2011-0908.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2011-0910.html","name":"http://www.redhat.com/support/errata/RHSA-2011-0910.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/trunk/ext/bigdecimal/bigdecimal.c?r1=29364&r2=30993","name":"http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/trunk/ext/bigdecimal/bigdecimal.c?r1=29364&r2=30993","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"ViewVC Exception","mime":"text/html","httpstatus":"200","archivestatus":"403"},{"url":"http://support.apple.com/kb/HT4581","name":"http://support.apple.com/kb/HT4581","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"About the security content of Mac OS X v10.6.7 and Security Update 2011-001","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2011-0909.html","name":"http://www.redhat.com/support/errata/RHSA-2011-0909.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:097","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:097","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Support / Security / Advisories /  / MDVSA-2011:097 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-0188","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-0188","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"188","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.5.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.6.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.6.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.6.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.6.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.6.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.6.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x_server","cpe6":"10.5.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x_server","cpe6":"10.6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x_server","cpe6":"10.6.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x_server","cpe6":"10.6.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x_server","cpe6":"10.6.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x_server","cpe6":"10.6.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x_server","cpe6":"10.6.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x_server","cpe6":"10.6.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"1.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"1.9","cpe7":"r18423","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"1.9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"1.9.0","cpe7":"r18423","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"1.9.0-0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"1.9.0-1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"1.9.0-2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"1.9.0-20060415","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"1.9.0-20070709","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"1.9.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"1.9.1","cpe7":"-p0","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"1.9.1","cpe7":"-p129","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"1.9.1","cpe7":"-p243","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"1.9.1","cpe7":"-p376","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"1.9.1","cpe7":"-p429","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"1.9.1","cpe7":"-preview_1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"1.9.1","cpe7":"-preview_2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"1.9.1","cpe7":"-rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"1.9.1","cpe7":"-rc2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"1.9.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"1.9.2","cpe7":"dev","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"188","vulnerable":"1","versionEndIncluding":"1.9.2-p136","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ruby-lang","cpe5":"ruby","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T21:43:15.487Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"RHSA-2011:0910","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2011-0910.html"},{"name":"1025236","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1025236"},{"name":"MDVSA-2011:098","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:098"},{"name":"RHSA-2011:0909","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2011-0909.html"},{"name":"APPLE-SA-2011-03-21-1","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html"},{"name":"RHSA-2011:0908","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2011-0908.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=682332"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/trunk/ext/bigdecimal/bigdecimal.c?r1=29364&r2=30993"},{"name":"MDVSA-2011:097","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:097"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT4581"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-03-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Ruby 1.9.2-p136 and earlier, as used on Apple Mac OS X before 10.6.7 and other platforms, does not properly allocate memory, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving creation of a large BigDecimal value within a 64-bit process, related to an \"integer truncation issue.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2011-04-21T09:00:00.000Z","orgId":"286789f9-fbc2-4510-9f9a-43facdede74c","shortName":"apple"},"references":[{"name":"RHSA-2011:0910","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2011-0910.html"},{"name":"1025236","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1025236"},{"name":"MDVSA-2011:098","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:098"},{"name":"RHSA-2011:0909","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2011-0909.html"},{"name":"APPLE-SA-2011-03-21-1","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html"},{"name":"RHSA-2011:0908","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2011-0908.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=682332"},{"tags":["x_refsource_CONFIRM"],"url":"http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/trunk/ext/bigdecimal/bigdecimal.c?r1=29364&r2=30993"},{"name":"MDVSA-2011:097","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:097"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT4581"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"product-security@apple.com","ID":"CVE-2011-0188","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Ruby 1.9.2-p136 and earlier, as used on Apple Mac OS X before 10.6.7 and other platforms, does not properly allocate memory, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving creation of a large BigDecimal value within a 64-bit process, related to an \"integer truncation issue.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"RHSA-2011:0910","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2011-0910.html"},{"name":"1025236","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1025236"},{"name":"MDVSA-2011:098","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:098"},{"name":"RHSA-2011:0909","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2011-0909.html"},{"name":"APPLE-SA-2011-03-21-1","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html"},{"name":"RHSA-2011:0908","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2011-0908.html"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=682332","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=682332"},{"name":"http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/trunk/ext/bigdecimal/bigdecimal.c?r1=29364&r2=30993","refsource":"CONFIRM","url":"http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/trunk/ext/bigdecimal/bigdecimal.c?r1=29364&r2=30993"},{"name":"MDVSA-2011:097","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:097"},{"name":"http://support.apple.com/kb/HT4581","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT4581"}]}}}},"cveMetadata":{"assignerOrgId":"286789f9-fbc2-4510-9f9a-43facdede74c","assignerShortName":"apple","cveId":"CVE-2011-0188","datePublished":"2011-03-23T01:00:00.000Z","dateReserved":"2010-12-23T00:00:00.000Z","dateUpdated":"2024-08-06T21:43:15.487Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-03-23 02:00:06","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-189","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*","versionEndIncluding":"1.9.2-p136","matchCriteriaId":"7999259C-95F6-474B-A828-1DEBFD20236D"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9:*:*:*:*:*:*:*","matchCriteriaId":"D9237145-35F8-4E05-B730-77C0F386E5B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9:r18423:*:*:*:*:*:*","matchCriteriaId":"11743FC1-0DD5-4946-AECF-C9962BF7C21F"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9.0:*:*:*:*:*:*:*","matchCriteriaId":"52179EC7-CAF0-42AA-A21A-7105E10CA122"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9.0:r18423:*:*:*:*:*:*","matchCriteriaId":"D906EA97-7071-4CFA-84EF-EC82D813D7AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9.0-0:*:*:*:*:*:*:*","matchCriteriaId":"A2D5127F-1E79-4F83-8BB0-C479B6CFE9AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9.0-1:*:*:*:*:*:*:*","matchCriteriaId":"31181BA2-71A7-40C8-9E08-8FEAB013977B"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9.0-2:*:*:*:*:*:*:*","matchCriteriaId":"EB8F3772-C973-41DB-AB3A-F4323418FC7F"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9.0-20060415:*:*:*:*:*:*:*","matchCriteriaId":"A688B357-7096-4362-A7DD-5A24FB0AF431"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9.0-20070709:*:*:*:*:*:*:*","matchCriteriaId":"46913DE9-8AE6-40E5-AEA1-6D2524EE7581"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9.1:*:*:*:*:*:*:*","matchCriteriaId":"C78BB1D8-0505-484D-B824-1AA219F8B247"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9.1:-p0:*:*:*:*:*:*","matchCriteriaId":"470CF526-96F6-4DD1-B687-17106051A6D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9.1:-p129:*:*:*:*:*:*","matchCriteriaId":"52159D9F-8CD3-4103-82E6-BDE035BA3625"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9.1:-p243:*:*:*:*:*:*","matchCriteriaId":"EC0FD3F8-73A3-4518-8892-1E34D709FB89"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9.1:-p376:*:*:*:*:*:*","matchCriteriaId":"4B846CCE-7D1D-4A7E-95D8-50F92CF79AC6"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9.1:-p429:*:*:*:*:*:*","matchCriteriaId":"CB99DD31-7355-4FF1-AE41-CC156F83D7A2"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9.1:-preview_1:*:*:*:*:*:*","matchCriteriaId":"A7E15263-74D3-42D4-B37C-C649F68EDECC"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9.1:-preview_2:*:*:*:*:*:*","matchCriteriaId":"BA7FEA9B-06CE-4D08-9D61-2526ED5AE630"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9.1:-rc1:*:*:*:*:*:*","matchCriteriaId":"0D7F7EA5-7F6C-4C15-AB97-024836DC4862"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9.1:-rc2:*:*:*:*:*:*","matchCriteriaId":"236B38D1-0CCA-43C5-B2FC-1224F4F4E165"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9.2:*:*:*:*:*:*:*","matchCriteriaId":"5178D04D-1C29-4353-8987-559AA07443EC"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9.2:dev:*:*:*:*:*:*","matchCriteriaId":"D19F541D-98C2-42A6-9364-D6D9A279796E"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x:10.5.8:*:*:*:*:*:*:*","matchCriteriaId":"1335E35A-D381-4056-9E78-37BC6DF8AD98"},{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x:10.6.0:*:*:*:*:*:*:*","matchCriteriaId":"3C69DEE9-3FA5-408E-AD27-F5E7043F852A"},{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x:10.6.1:*:*:*:*:*:*:*","matchCriteriaId":"D25D1FD3-C291-492C-83A7-0AFAFAADC98D"},{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x:10.6.2:*:*:*:*:*:*:*","matchCriteriaId":"5B565F77-C310-4B83-B098-22F9489C226C"},{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x:10.6.3:*:*:*:*:*:*:*","matchCriteriaId":"546EBFC8-79F0-42C2-9B9A-A76CA3F19470"},{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x:10.6.4:*:*:*:*:*:*:*","matchCriteriaId":"119C8089-8C98-472E-9E9C-1741AA21DD35"},{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x:10.6.5:*:*:*:*:*:*:*","matchCriteriaId":"831C5105-6409-4743-8FB5-A91D8956202F"},{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x:10.6.6:*:*:*:*:*:*:*","matchCriteriaId":"0B63D169-E2AA-4315-891F-B4AF99F2753C"},{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x_server:10.5.8:*:*:*:*:*:*:*","matchCriteriaId":"82B4CD59-9F37-4EF0-BA43-427CFD6E1329"},{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x_server:10.6.0:*:*:*:*:*:*:*","matchCriteriaId":"26E34E35-CCE9-42BE-9AFF-561D8AA90E25"},{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x_server:10.6.1:*:*:*:*:*:*:*","matchCriteriaId":"A04FF6EE-D4DA-4D70-B0CE-154292828531"},{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x_server:10.6.2:*:*:*:*:*:*:*","matchCriteriaId":"9425320F-D119-49EB-9265-3159070DFE93"},{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x_server:10.6.3:*:*:*:*:*:*:*","matchCriteriaId":"F6BE138D-619B-4E44-BFB2-8DFE5F0D1E12"},{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x_server:10.6.4:*:*:*:*:*:*:*","matchCriteriaId":"EF0D1051-F850-4A02-ABA0-968E1336A518"},{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x_server:10.6.5:*:*:*:*:*:*:*","matchCriteriaId":"A1C9705A-74D4-43BA-A119-C667678F9A15"},{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x_server:10.6.6:*:*:*:*:*:*:*","matchCriteriaId":"4BBF5FE5-4B25-47BE-8D9D-F228746408EC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"188","Ordinal":"1","Title":"CVE-2011-0188","CVE":"CVE-2011-0188","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"188","Ordinal":"1","NoteData":"The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Ruby 1.9.2-p136 and earlier, as used on Apple Mac OS X before 10.6.7 and other platforms, does not properly allocate memory, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving creation of a large BigDecimal value within a 64-bit process, related to an \"integer truncation issue.\"","Type":"Description","Title":"CVE-2011-0188"},{"CveYear":"2011","CveId":"188","Ordinal":"2","NoteData":"2011-03-22","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"188","Ordinal":"3","NoteData":"2011-04-21","Type":"Other","Title":"Modified"}]}}}