Lucene search

K
cveRedhatCVE-2008-2376
HistoryJul 09, 2008 - 12:41 a.m.

CVE-2008-2376

2008-07-0900:41:00
CWE-189
redhat
web.nvd.nist.gov
43
cve-2008-2376
integer overflow
rb_ary_fill function
ruby
denial of service
array#fill method
ary_max_size.

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

High

EPSS

0.021

Percentile

89.0%

Integer overflow in the rb_ary_fill function in array.c in Ruby before revision 17756 allows context-dependent attackers to cause a denial of service (crash) or possibly have unspecified other impact via a call to the Array#fill method with a start (aka beg) argument greater than ARY_MAX_SIZE. NOTE: this issue exists because of an incomplete fix for other closely related integer overflows.

Affected configurations

Nvd
Node
redhatfedora_8Match1.8.6.230
AND
ruby-langrubyMatch1.8.6.230
VendorProductVersionCPE
redhatfedora_81.8.6.230cpe:2.3:o:redhat:fedora_8:1.8.6.230:*:*:*:*:*:*:*
ruby-langruby1.8.6.230cpe:2.3:a:ruby-lang:ruby:1.8.6.230:*:*:*:*:*:*:*

References

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

High

EPSS

0.021

Percentile

89.0%