CVE
- Id
- 32781
- CVE No.
- CVE-2008-2664
- Status
- Candidate
- Description
- The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allows context-dependent attackers to trigger memory corruption via unspecified vectors related to alloca, a different issue than CVE-2008-2662, CVE-2008-2663, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.
- Phase
- Assigned (20080610)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
354769 | 32781 | CVE-2008-2664 | BUGTRAQ:20080626 rPSA-2008-0206-1 ruby | View |
354770 | 32781 | CVE-2008-2664 | URL:http://www.securityfocus.com/archive/1/archive/1/493688/100/0/threaded | View |
354771 | 32781 | CVE-2008-2664 | MISC:http://blog.phusion.nl/2008/06/23/ruby-186-p230187-broke-your-app-ruby-enterprise-edition-to-the-rescue/ | View |
354772 | 32781 | CVE-2008-2664 | MISC:http://weblog.rubyonrails.org/2008/6/21/multiple-ruby-security-vulnerabilities | View |
354773 | 32781 | CVE-2008-2664 | MISC:http://www.matasano.com/log/1070/updates-on-drew-yaos-terrible-ruby-vulnerabilities/ | View |
354774 | 32781 | CVE-2008-2664 | MISC:http://www.ruby-forum.com/topic/157034 | View |
354775 | 32781 | CVE-2008-2664 | MISC:http://www.rubyinside.com/june-2008-ruby-security-vulnerabilities-927.html | View |
354776 | 32781 | CVE-2008-2664 | MISC:http://www.zedshaw.com/rants/the_big_ruby_vulnerabilities.html | View |
354777 | 32781 | CVE-2008-2664 | CONFIRM:http://www.ruby-lang.org/en/news/2008/06/20/arbitrary-code-execution-vulnerabilities/ | View |
354778 | 32781 | CVE-2008-2664 | CONFIRM:http://support.apple.com/kb/HT2163 | View |
354779 | 32781 | CVE-2008-2664 | CONFIRM:http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0206 | View |
354780 | 32781 | CVE-2008-2664 | CONFIRM:https://issues.rpath.com/browse/RPL-2626 | View |
354781 | 32781 | CVE-2008-2664 | APPLE:APPLE-SA-2008-06-30 | View |
354782 | 32781 | CVE-2008-2664 | URL:http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html | View |
354783 | 32781 | CVE-2008-2664 | DEBIAN:DSA-1612 | View |
354784 | 32781 | CVE-2008-2664 | URL:http://www.debian.org/security/2008/dsa-1612 | View |
354785 | 32781 | CVE-2008-2664 | DEBIAN:DSA-1618 | View |
354786 | 32781 | CVE-2008-2664 | URL:http://www.debian.org/security/2008/dsa-1618 | View |
354787 | 32781 | CVE-2008-2664 | FEDORA:FEDORA-2008-5649 | View |
354788 | 32781 | CVE-2008-2664 | URL:https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00937.html | View |
354789 | 32781 | CVE-2008-2664 | GENTOO:GLSA-200812-17 | View |
354790 | 32781 | CVE-2008-2664 | URL:http://security.gentoo.org/glsa/glsa-200812-17.xml | View |
354791 | 32781 | CVE-2008-2664 | MANDRIVA:MDVSA-2008:140 | View |
354792 | 32781 | CVE-2008-2664 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:140 | View |
354793 | 32781 | CVE-2008-2664 | MANDRIVA:MDVSA-2008:141 | View |
354794 | 32781 | CVE-2008-2664 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:141 | View |
354795 | 32781 | CVE-2008-2664 | MANDRIVA:MDVSA-2008:142 | View |
354796 | 32781 | CVE-2008-2664 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:142 | View |
354797 | 32781 | CVE-2008-2664 | REDHAT:RHSA-2008:0561 | View |
354798 | 32781 | CVE-2008-2664 | URL:http://www.redhat.com/support/errata/RHSA-2008-0561.html | View |
354799 | 32781 | CVE-2008-2664 | SLACKWARE:SSA:2008-179-01 | View |
354800 | 32781 | CVE-2008-2664 | URL:http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.429562 | View |
354801 | 32781 | CVE-2008-2664 | SUSE:SUSE-SR:2008:017 | View |
354802 | 32781 | CVE-2008-2664 | URL:http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html | View |
354803 | 32781 | CVE-2008-2664 | UBUNTU:USN-621-1 | View |
354804 | 32781 | CVE-2008-2664 | URL:http://www.ubuntu.com/usn/usn-621-1 | View |
354805 | 32781 | CVE-2008-2664 | BID:29903 | View |
354806 | 32781 | CVE-2008-2664 | URL:http://www.securityfocus.com/bid/29903 | View |
354807 | 32781 | CVE-2008-2664 | OVAL:oval:org.mitre.oval:def:9646 | View |
354808 | 32781 | CVE-2008-2664 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9646 | View |
354809 | 32781 | CVE-2008-2664 | VUPEN:ADV-2008-1907 | View |
354810 | 32781 | CVE-2008-2664 | URL:http://www.vupen.com/english/advisories/2008/1907/references | View |
354811 | 32781 | CVE-2008-2664 | VUPEN:ADV-2008-1981 | View |
354812 | 32781 | CVE-2008-2664 | URL:http://www.vupen.com/english/advisories/2008/1981/references | View |
354813 | 32781 | CVE-2008-2664 | SECTRACK:1020347 | View |
354814 | 32781 | CVE-2008-2664 | URL:http://www.securitytracker.com/id?1020347 | View |
354815 | 32781 | CVE-2008-2664 | SECUNIA:30831 | View |
354816 | 32781 | CVE-2008-2664 | URL:http://secunia.com/advisories/30831 | View |
354817 | 32781 | CVE-2008-2664 | SECUNIA:30802 | View |
354818 | 32781 | CVE-2008-2664 | URL:http://secunia.com/advisories/30802 | View |
354819 | 32781 | CVE-2008-2664 | SECUNIA:31062 | View |
354820 | 32781 | CVE-2008-2664 | URL:http://secunia.com/advisories/31062 | View |
354821 | 32781 | CVE-2008-2664 | SECUNIA:31090 | View |
354822 | 32781 | CVE-2008-2664 | URL:http://secunia.com/advisories/31090 | View |
354823 | 32781 | CVE-2008-2664 | SECUNIA:31181 | View |
354824 | 32781 | CVE-2008-2664 | URL:http://secunia.com/advisories/31181 | View |
354825 | 32781 | CVE-2008-2664 | SECUNIA:31256 | View |
354826 | 32781 | CVE-2008-2664 | URL:http://secunia.com/advisories/31256 | View |
354827 | 32781 | CVE-2008-2664 | SECUNIA:31687 | View |
354828 | 32781 | CVE-2008-2664 | URL:http://secunia.com/advisories/31687 | View |
354829 | 32781 | CVE-2008-2664 | SECUNIA:30867 | View |
354830 | 32781 | CVE-2008-2664 | URL:http://secunia.com/advisories/30867 | View |
354831 | 32781 | CVE-2008-2664 | SECUNIA:30875 | View |
354832 | 32781 | CVE-2008-2664 | URL:http://secunia.com/advisories/30875 | View |
354833 | 32781 | CVE-2008-2664 | SECUNIA:30894 | View |
354834 | 32781 | CVE-2008-2664 | URL:http://secunia.com/advisories/30894 | View |
354835 | 32781 | CVE-2008-2664 | SECUNIA:33178 | View |
354836 | 32781 | CVE-2008-2664 | URL:http://secunia.com/advisories/33178 | View |
354837 | 32781 | CVE-2008-2664 | XF:ruby-rbstrformat-code-execution(43348) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
50567 | JVNDB-2008-005877 | yBlog におけるクロスサイトスクリプティングの脆弱性 | Yblog には、クロスサイトスクリプティングの脆弱性が存在します。 | CVE-2008-2668 | 32781 | 4.3 | http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-005877.html | View |