Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
Vulnerability Description
Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves state.start, state.cursor, and state.end pointing into released storage. When partial_value reconstructs an incomplete object containing duplicate keys, the duplicate-key warning path calls cursor_position, which dereferences those stale pointers. This results in a heap-use-after-free and can terminate the Ruby process. An attacker who can supply JSON stream data to an application using JSON::ResumableParser may cause process termination when the application calls partial_value on incomplete attacker-controlled input containing duplicate object keys. This issue has been fixed in version 2.21.2.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
释放后使用
Vulnerability Title
Ruby json 资源管理错误漏洞
Vulnerability Description
Ruby json是Ruby组织的一款处理JSON数据的软件。 Ruby json 2.20.0版本至2.21.2之前版本存在资源管理错误漏洞,该漏洞源于Ruby JSON原生C扩展在清除已消费的JSON::ResumableParser输入缓冲区后,state.start、state.cursor和state.end仍指向已释放的存储,导致处理包含重复键的不完整对象时发生堆释放后重用,攻击者通过向使用JSON::ResumableParser的应用程序提供恶意JSON流数据,可导致进程终止。
CVSS Information
N/A
Vulnerability Type
N/A