CVE-2016-2337
06.01.2017, 21:59
Type confusion exists in _cancel_eval Ruby's TclTkIp class method. Attacker passing different type of object than String as "retval" argument can cause arbitrary code execution.Enginsight
| Vendor | Product | Version |
|---|---|---|
| ruby-lang | ruby | 2.2.2 |
| ruby-lang | ruby | 2.3.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| ruby1.8 |
| ||||||||||
| ruby1.9.1 |
| ||||||||||
| ruby2.0 |
| ||||||||||
| ruby2.3 |
|
References