Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_GETUPVAR in the presence of deep scope nesting, resulting in a use-after-free. An attacker that can cause Ruby code to be run can use this to possibly execute arbitrary code.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
mruby 数字错误漏洞
Vulnerability Description
mruby是一个Ruby语言的轻量级实现。 mruby及之前1.4.0版本中的src/vm.c的‘mrb_vm_exec()’函数存在整数溢出漏洞。攻击者可利用该漏洞执行任意代码(释放后重用)。
CVSS Information
N/A
Vulnerability Type
N/A