CVE-2008-2376

Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 09 Jul 2008, 00:00
Last modified:07 Aug 2024, 08:58

Vulnerability Summary

Overall Risk (default)
medium
32/100
CVSS Score
7.5 HIGH
v2.0 (nvd)
EPSS Score
11.36% MEDIUM
11% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Jul 2008, 00:00
Published
Vulnerability first disclosed
07 Aug 2024, 08:58
Last Modified
Vulnerability information updated

Description

Integer overflow in the rb_ary_fill function in array.c in Ruby before revision 17756 allows context-dependent attackers to cause a denial of service (crash) or possibly have unspecified other impact via a call to the Array#fill method with a start (aka beg) argument greater than ARY_MAX_SIZE. NOTE: this issue exists because of an incomplete fix for other closely related integer overflows.

CVSS Metrics

  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 11.36% Percentile: 94%

Techniques & Countermeasures

  • CWE-189Numeric Errors

    Weaknesses in this category are related to improper calculation or conversion of numbers.

Affected Systems

  • ruby-langruby

    1.8.6.230

References (28)