Ruby 'string.c' Remote Memory Corruption Vulnerability
BID:67705
Info
Ruby 'string.c' Remote Memory Corruption Vulnerability
| Bugtraq ID: | 67705 |
| Class: | Design Error |
| CVE: |
CVE-2014-3916 |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2014 12:00AM |
| Updated: | May 27 2014 12:00AM |
| Credit: | Hiroshi Shirosaki |
| Vulnerable: |
Ruby-Lang Ruby 2.0 rc2 Ruby-Lang Ruby 1.8.7 p72 Ruby-Lang Ruby 1.8.7 p71 Ruby-Lang Ruby 2.2.0dev Ruby-Lang Ruby 2.1.1 Ruby-Lang Ruby 2.1 Preview1 Ruby-Lang Ruby 2.0.0 RC1 Ruby-Lang Ruby 2.0.0 Preview2 Ruby-Lang Ruby 2.0.0 Preview1 Ruby-Lang Ruby 2.0.0 P247 Ruby-Lang Ruby 2.0.0 P195 Ruby-Lang Ruby 2.0.0 P0 Ruby-Lang Ruby 2.0.0 Ruby-Lang Ruby 1.9.3 P429 Ruby-Lang Ruby 1.9.3 P426 Ruby-Lang Ruby 1.9.3 P392 Ruby-Lang Ruby 1.9.3 P385 Ruby-Lang Ruby 1.9.3 P383 Ruby-Lang Ruby 1.9.3 P286 Ruby-Lang Ruby 1.9.3 P194 Ruby-Lang Ruby 1.9.3 P125 Ruby-Lang Ruby 1.9.3 P0 Ruby-Lang Ruby 1.9.3 Ruby-Lang Ruby 1.9.2 Ruby-Lang Ruby 1.9.1 Ruby-Lang Ruby 1.9 Ruby-Lang Ruby 1.8.7 Preview4 Ruby-Lang Ruby 1.8.7 Preview3 Ruby-Lang Ruby 1.8.7 Preview2 Ruby-Lang Ruby 1.8.7 Preview1 Ruby-Lang Ruby 1.8.7 P374 Ruby-Lang Ruby 1.8.7 P373 Ruby-Lang Ruby 1.8.7 P371 Ruby-Lang Ruby 1.8.7 P370 Ruby-Lang Ruby 1.8.7 P358 Ruby-Lang Ruby 1.8.7 P357 Ruby-Lang Ruby 1.8.7 P352 Ruby-Lang Ruby 1.8.7 P334 Ruby-Lang Ruby 1.8.7 P330 Ruby-Lang Ruby 1.8.7 P302 Ruby-Lang Ruby 1.8.7 P301 Ruby-Lang Ruby 1.8.7 P299 Ruby-Lang Ruby 1.8.7 P249 Ruby-Lang Ruby 1.8.7 P248 Ruby-Lang Ruby 1.8.7 P22 Ruby-Lang Ruby 1.8.7 P174 Ruby-Lang Ruby 1.8.7 P173 Ruby-Lang Ruby 1.8.7 P17 Ruby-Lang Ruby 1.8.7 P160 Ruby-Lang Ruby 1.8.7 Ruby-Lang Ruby 1.8.6-26 Ruby-Lang Ruby 1.8 |
| Not Vulnerable: | |
Discussion
Ruby 'string.c' Remote Memory Corruption Vulnerability
Ruby is prone to a remote memory-corruption vulnerability.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users. Due to the nature of this issue, arbitrary code execution may be possible; however, this has not been confirmed.
Ruby is prone to a remote memory-corruption vulnerability.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users. Due to the nature of this issue, arbitrary code execution may be possible; however, this has not been confirmed.
Exploit / POC
Ruby 'string.c' Remote Memory Corruption Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].