Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The parser_yyerror function in the UTF-8 parser in Ruby 2.4.1 allows attackers to cause a denial of service (invalid write or read) or possibly have unspecified other impact via a crafted Ruby script, related to the parser_tokadd_utf8 function in parse.y. NOTE: this might have security relevance as a bypass of a $SAFE protection mechanism.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ruby UTF-8解析器安全漏洞
Vulnerability Description
Ruby是日本软件开发者松本行弘所研发的一种跨平台、面向对象的动态类型编程语言。UTF-8 parser是其中的一个UTF-8编码解析器。 Ruby 2.4.1版本中的UTF-8解析器的‘parser_yyerror’函数存在安全漏洞。攻击者可借助特制的Ruby脚本利用该漏洞造成拒绝服务(无效写入和读取)。
CVSS Information
N/A
Vulnerability Type
N/A