Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors that trigger memory corruption, a different issue than CVE-2008-2663, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. This CVE description should be regarded as authoritative, although it is likely to change.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ruby rb_str_buf_append()函数多个整数溢出漏洞
Vulnerability Description
Ruby是一种功能强大的面向对象的脚本语言。 Ruby 1.8.4 以及之前版本,1.8.5-p231 之前的1.8.5, 1.8.6-p230之前的 1.8.6,1.8.7-p22 之前的 1.8.7版本,1.9.0-2 之前的1.9.0 版本,其 rb_str_buf_append 函数存在多个整数溢出漏洞,允许攻击者通过上下文关联造成拒绝服务攻击或执行任意代码。 注意:作为 20080624,出现了多个与 Ruby 相关的 CVE 标识符不一致的情况。CVE描述应被视为权威,虽然它可能会发生变化。
CVSS Information
N/A
Vulnerability Type
N/A