CVE-2014-3916

The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
VendorProductVersion
rubyonrailsrails
1.9.3
rubyonrailsrails
2.0.0
rubyonrailsrails
2.1.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ruby1.8
trusty
dne
saucy
ignored
precise
ignored
lucid
ignored
ruby1.9.1
trusty
dne
saucy
ignored
precise
ignored
lucid
ignored
ruby2.0
trusty
dne
saucy
ignored
precise
dne
lucid
dne
ruby2.1
trusty
dne
saucy
dne
precise
dne
lucid
dne
Common Weakness Enumeration