CVE
- Id
- 32779
- CVE No.
- CVE-2008-2662
- Status
- Candidate
- Description
- Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors that trigger memory corruption, a different issue than CVE-2008-2663, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. This CVE description should be regarded as authoritative, although it is likely to change.
- Phase
- Assigned (20080610)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
354633 | 32779 | CVE-2008-2662 | BUGTRAQ:20080626 rPSA-2008-0206-1 ruby | View |
354634 | 32779 | CVE-2008-2662 | URL:http://www.securityfocus.com/archive/1/archive/1/493688/100/0/threaded | View |
354635 | 32779 | CVE-2008-2662 | MISC:http://blog.phusion.nl/2008/06/23/ruby-186-p230187-broke-your-app-ruby-enterprise-edition-to-the-rescue/ | View |
354636 | 32779 | CVE-2008-2662 | MISC:http://weblog.rubyonrails.org/2008/6/21/multiple-ruby-security-vulnerabilities | View |
354637 | 32779 | CVE-2008-2662 | MISC:http://www.matasano.com/log/1070/updates-on-drew-yaos-terrible-ruby-vulnerabilities/ | View |
354638 | 32779 | CVE-2008-2662 | MISC:http://www.ruby-forum.com/topic/157034 | View |
354639 | 32779 | CVE-2008-2662 | MISC:http://www.rubyinside.com/june-2008-ruby-security-vulnerabilities-927.html | View |
354640 | 32779 | CVE-2008-2662 | MISC:http://www.zedshaw.com/rants/the_big_ruby_vulnerabilities.html | View |
354641 | 32779 | CVE-2008-2662 | CONFIRM:http://www.ruby-lang.org/en/news/2008/06/20/arbitrary-code-execution-vulnerabilities/ | View |
354642 | 32779 | CVE-2008-2662 | CONFIRM:http://support.apple.com/kb/HT2163 | View |
354643 | 32779 | CVE-2008-2662 | CONFIRM:http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0206 | View |
354644 | 32779 | CVE-2008-2662 | CONFIRM:https://issues.rpath.com/browse/RPL-2626 | View |
354645 | 32779 | CVE-2008-2662 | APPLE:APPLE-SA-2008-06-30 | View |
354646 | 32779 | CVE-2008-2662 | URL:http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html | View |
354647 | 32779 | CVE-2008-2662 | DEBIAN:DSA-1612 | View |
354648 | 32779 | CVE-2008-2662 | URL:http://www.debian.org/security/2008/dsa-1612 | View |
354649 | 32779 | CVE-2008-2662 | DEBIAN:DSA-1618 | View |
354650 | 32779 | CVE-2008-2662 | URL:http://www.debian.org/security/2008/dsa-1618 | View |
354651 | 32779 | CVE-2008-2662 | FEDORA:FEDORA-2008-5649 | View |
354652 | 32779 | CVE-2008-2662 | URL:https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00937.html | View |
354653 | 32779 | CVE-2008-2662 | GENTOO:GLSA-200812-17 | View |
354654 | 32779 | CVE-2008-2662 | URL:http://security.gentoo.org/glsa/glsa-200812-17.xml | View |
354655 | 32779 | CVE-2008-2662 | MANDRIVA:MDVSA-2008:140 | View |
354656 | 32779 | CVE-2008-2662 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:140 | View |
354657 | 32779 | CVE-2008-2662 | MANDRIVA:MDVSA-2008:141 | View |
354658 | 32779 | CVE-2008-2662 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:141 | View |
354659 | 32779 | CVE-2008-2662 | MANDRIVA:MDVSA-2008:142 | View |
354660 | 32779 | CVE-2008-2662 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:142 | View |
354661 | 32779 | CVE-2008-2662 | REDHAT:RHSA-2008:0561 | View |
354662 | 32779 | CVE-2008-2662 | URL:http://www.redhat.com/support/errata/RHSA-2008-0561.html | View |
354663 | 32779 | CVE-2008-2662 | SLACKWARE:SSA:2008-179-01 | View |
354664 | 32779 | CVE-2008-2662 | URL:http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.429562 | View |
354665 | 32779 | CVE-2008-2662 | SUSE:SUSE-SR:2008:017 | View |
354666 | 32779 | CVE-2008-2662 | URL:http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html | View |
354667 | 32779 | CVE-2008-2662 | UBUNTU:USN-621-1 | View |
354668 | 32779 | CVE-2008-2662 | URL:http://www.ubuntu.com/usn/usn-621-1 | View |
354669 | 32779 | CVE-2008-2662 | BID:29903 | View |
354670 | 32779 | CVE-2008-2662 | URL:http://www.securityfocus.com/bid/29903 | View |
354671 | 32779 | CVE-2008-2662 | OVAL:oval:org.mitre.oval:def:11601 | View |
354672 | 32779 | CVE-2008-2662 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11601 | View |
354673 | 32779 | CVE-2008-2662 | VUPEN:ADV-2008-1907 | View |
354674 | 32779 | CVE-2008-2662 | URL:http://www.vupen.com/english/advisories/2008/1907/references | View |
354675 | 32779 | CVE-2008-2662 | VUPEN:ADV-2008-1981 | View |
354676 | 32779 | CVE-2008-2662 | URL:http://www.vupen.com/english/advisories/2008/1981/references | View |
354677 | 32779 | CVE-2008-2662 | SECTRACK:1020347 | View |
354678 | 32779 | CVE-2008-2662 | URL:http://www.securitytracker.com/id?1020347 | View |
354679 | 32779 | CVE-2008-2662 | SECUNIA:30831 | View |
354680 | 32779 | CVE-2008-2662 | URL:http://secunia.com/advisories/30831 | View |
354681 | 32779 | CVE-2008-2662 | SECUNIA:30802 | View |
354682 | 32779 | CVE-2008-2662 | URL:http://secunia.com/advisories/30802 | View |
354683 | 32779 | CVE-2008-2662 | SECUNIA:31062 | View |
354684 | 32779 | CVE-2008-2662 | URL:http://secunia.com/advisories/31062 | View |
354685 | 32779 | CVE-2008-2662 | SECUNIA:31181 | View |
354686 | 32779 | CVE-2008-2662 | URL:http://secunia.com/advisories/31181 | View |
354687 | 32779 | CVE-2008-2662 | SECUNIA:31256 | View |
354688 | 32779 | CVE-2008-2662 | URL:http://secunia.com/advisories/31256 | View |
354689 | 32779 | CVE-2008-2662 | SECUNIA:31687 | View |
354690 | 32779 | CVE-2008-2662 | URL:http://secunia.com/advisories/31687 | View |
354691 | 32779 | CVE-2008-2662 | SECUNIA:30867 | View |
354692 | 32779 | CVE-2008-2662 | URL:http://secunia.com/advisories/30867 | View |
354693 | 32779 | CVE-2008-2662 | SECUNIA:30875 | View |
354694 | 32779 | CVE-2008-2662 | URL:http://secunia.com/advisories/30875 | View |
354695 | 32779 | CVE-2008-2662 | SECUNIA:30894 | View |
354696 | 32779 | CVE-2008-2662 | URL:http://secunia.com/advisories/30894 | View |
354697 | 32779 | CVE-2008-2662 | SECUNIA:33178 | View |
354698 | 32779 | CVE-2008-2662 | URL:http://secunia.com/advisories/33178 | View |
354699 | 32779 | CVE-2008-2662 | XF:ruby-rbstrbufappend-code-execution(43345) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
46857 | JVNDB-2008-002167 | PHP の chdir 関数および ftok 関数におけるディレクトリトラバーサルの脆弱性 | PHP には、chdir 関数および ftok 関数において、http URL 内の "../" の処理に不備があるため、ディレクトリトラバーサルの脆弱性が存在します。 | CVE-2008-2666 | 32779 | 5 | http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002167.html | View |