CVE-2016-2337
06.01.2017, 21:59
Type confusion exists in _cancel_eval Ruby's TclTkIp class method. Attacker passing different type of object than String as "retval" argument can cause arbitrary code execution.Enginsight
Vendor | Product | Version |
---|---|---|
ruby-lang | ruby | 2.2.2 |
ruby-lang | ruby | 2.3.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
ruby1.8 |
| ||||||||||
ruby1.9.1 |
| ||||||||||
ruby2.0 |
| ||||||||||
ruby2.3 |
|
References