CVE
- Id
- 32780
- CVE No.
- CVE-2008-2663
- Status
- Candidate
- Description
- Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors, a different issue than CVE-2008-2662, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.
- Phase
- Assigned (20080610)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
354700 | 32780 | CVE-2008-2663 | BUGTRAQ:20080626 rPSA-2008-0206-1 ruby | View |
354701 | 32780 | CVE-2008-2663 | URL:http://www.securityfocus.com/archive/1/archive/1/493688/100/0/threaded | View |
354702 | 32780 | CVE-2008-2663 | MISC:http://blog.phusion.nl/2008/06/23/ruby-186-p230187-broke-your-app-ruby-enterprise-edition-to-the-rescue/ | View |
354703 | 32780 | CVE-2008-2663 | MISC:http://weblog.rubyonrails.org/2008/6/21/multiple-ruby-security-vulnerabilities | View |
354704 | 32780 | CVE-2008-2663 | MISC:http://www.matasano.com/log/1070/updates-on-drew-yaos-terrible-ruby-vulnerabilities/ | View |
354705 | 32780 | CVE-2008-2663 | MISC:http://www.ruby-forum.com/topic/157034 | View |
354706 | 32780 | CVE-2008-2663 | MISC:http://www.rubyinside.com/june-2008-ruby-security-vulnerabilities-927.html | View |
354707 | 32780 | CVE-2008-2663 | MISC:http://www.zedshaw.com/rants/the_big_ruby_vulnerabilities.html | View |
354708 | 32780 | CVE-2008-2663 | CONFIRM:http://www.ruby-lang.org/en/news/2008/06/20/arbitrary-code-execution-vulnerabilities/ | View |
354709 | 32780 | CVE-2008-2663 | CONFIRM:http://support.apple.com/kb/HT2163 | View |
354710 | 32780 | CVE-2008-2663 | CONFIRM:http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0206 | View |
354711 | 32780 | CVE-2008-2663 | CONFIRM:https://issues.rpath.com/browse/RPL-2626 | View |
354712 | 32780 | CVE-2008-2663 | APPLE:APPLE-SA-2008-06-30 | View |
354713 | 32780 | CVE-2008-2663 | URL:http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html | View |
354714 | 32780 | CVE-2008-2663 | DEBIAN:DSA-1612 | View |
354715 | 32780 | CVE-2008-2663 | URL:http://www.debian.org/security/2008/dsa-1612 | View |
354716 | 32780 | CVE-2008-2663 | DEBIAN:DSA-1618 | View |
354717 | 32780 | CVE-2008-2663 | URL:http://www.debian.org/security/2008/dsa-1618 | View |
354718 | 32780 | CVE-2008-2663 | FEDORA:FEDORA-2008-5649 | View |
354719 | 32780 | CVE-2008-2663 | URL:https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00937.html | View |
354720 | 32780 | CVE-2008-2663 | GENTOO:GLSA-200812-17 | View |
354721 | 32780 | CVE-2008-2663 | URL:http://security.gentoo.org/glsa/glsa-200812-17.xml | View |
354722 | 32780 | CVE-2008-2663 | MANDRIVA:MDVSA-2008:140 | View |
354723 | 32780 | CVE-2008-2663 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:140 | View |
354724 | 32780 | CVE-2008-2663 | MANDRIVA:MDVSA-2008:141 | View |
354725 | 32780 | CVE-2008-2663 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:141 | View |
354726 | 32780 | CVE-2008-2663 | MANDRIVA:MDVSA-2008:142 | View |
354727 | 32780 | CVE-2008-2663 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:142 | View |
354728 | 32780 | CVE-2008-2663 | REDHAT:RHSA-2008:0561 | View |
354729 | 32780 | CVE-2008-2663 | URL:http://www.redhat.com/support/errata/RHSA-2008-0561.html | View |
354730 | 32780 | CVE-2008-2663 | SLACKWARE:SSA:2008-179-01 | View |
354731 | 32780 | CVE-2008-2663 | URL:http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.429562 | View |
354732 | 32780 | CVE-2008-2663 | SUSE:SUSE-SR:2008:017 | View |
354733 | 32780 | CVE-2008-2663 | URL:http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html | View |
354734 | 32780 | CVE-2008-2663 | UBUNTU:USN-621-1 | View |
354735 | 32780 | CVE-2008-2663 | URL:http://www.ubuntu.com/usn/usn-621-1 | View |
354736 | 32780 | CVE-2008-2663 | BID:29903 | View |
354737 | 32780 | CVE-2008-2663 | URL:http://www.securityfocus.com/bid/29903 | View |
354738 | 32780 | CVE-2008-2663 | OVAL:oval:org.mitre.oval:def:10524 | View |
354739 | 32780 | CVE-2008-2663 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10524 | View |
354740 | 32780 | CVE-2008-2663 | VUPEN:ADV-2008-1907 | View |
354741 | 32780 | CVE-2008-2663 | URL:http://www.vupen.com/english/advisories/2008/1907/references | View |
354742 | 32780 | CVE-2008-2663 | VUPEN:ADV-2008-1981 | View |
354743 | 32780 | CVE-2008-2663 | URL:http://www.vupen.com/english/advisories/2008/1981/references | View |
354744 | 32780 | CVE-2008-2663 | SECTRACK:1020347 | View |
354745 | 32780 | CVE-2008-2663 | URL:http://www.securitytracker.com/id?1020347 | View |
354746 | 32780 | CVE-2008-2663 | SECUNIA:30831 | View |
354747 | 32780 | CVE-2008-2663 | URL:http://secunia.com/advisories/30831 | View |
354748 | 32780 | CVE-2008-2663 | SECUNIA:30802 | View |
354749 | 32780 | CVE-2008-2663 | URL:http://secunia.com/advisories/30802 | View |
354750 | 32780 | CVE-2008-2663 | SECUNIA:31062 | View |
354751 | 32780 | CVE-2008-2663 | URL:http://secunia.com/advisories/31062 | View |
354752 | 32780 | CVE-2008-2663 | SECUNIA:31090 | View |
354753 | 32780 | CVE-2008-2663 | URL:http://secunia.com/advisories/31090 | View |
354754 | 32780 | CVE-2008-2663 | SECUNIA:31181 | View |
354755 | 32780 | CVE-2008-2663 | URL:http://secunia.com/advisories/31181 | View |
354756 | 32780 | CVE-2008-2663 | SECUNIA:31256 | View |
354757 | 32780 | CVE-2008-2663 | URL:http://secunia.com/advisories/31256 | View |
354758 | 32780 | CVE-2008-2663 | SECUNIA:31687 | View |
354759 | 32780 | CVE-2008-2663 | URL:http://secunia.com/advisories/31687 | View |
354760 | 32780 | CVE-2008-2663 | SECUNIA:30867 | View |
354761 | 32780 | CVE-2008-2663 | URL:http://secunia.com/advisories/30867 | View |
354762 | 32780 | CVE-2008-2663 | SECUNIA:30875 | View |
354763 | 32780 | CVE-2008-2663 | URL:http://secunia.com/advisories/30875 | View |
354764 | 32780 | CVE-2008-2663 | SECUNIA:30894 | View |
354765 | 32780 | CVE-2008-2663 | URL:http://secunia.com/advisories/30894 | View |
354766 | 32780 | CVE-2008-2663 | SECUNIA:33178 | View |
354767 | 32780 | CVE-2008-2663 | URL:http://secunia.com/advisories/33178 | View |
354768 | 32780 | CVE-2008-2663 | XF:ruby-rbarystore-code-execution(43346) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
47838 | JVNDB-2008-003148 | SUSE openSUSE および他のプラットフォーム上の Courier Authentication Library における SQL インジェクションの脆弱性 | SUSE openSUSE および他のプラットフォーム上の Courier Authentication Library には、MySQL および非ラテン文字セットが使用されている際、SQL インジェクションの脆弱性が存在します。 | CVE-2008-2667 | 32780 | 5.1 | http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-003148.html | View |