CVE-2011-0188
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Ruby 1.9.2-p136 and earlier, as used on Apple Mac OS X before 10.6.7 and other platforms, does not properly allocate memory, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving creation of a large BigDecimal value within a 64-bit process, related to an "integer truncation issue."
Metrics
Affected operating systems
linux
debian / debian_linux10.0
linux
debian / debian_linux11.0
linux
debian / debian_linux9.0
linux
ubuntu / ruby2.3xenial
macos
apple / macos
other
fedoraproject / fedora36
other
fedoraproject / fedora37
other
fedoraproject / fedora38
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
bitnami
ruby-min2.6.0
bitnami
ruby-min2.7.0
bitnami
ruby-min3.0.0
bitnami
ruby-min3.1.0
bitnami
ruby-min3.2.0
bitnami
ruby-min3.3.0
bitnami
ruby-min
maven
org.jruby:jruby0.8.3
maven
org.jruby:jruby0.9.1
maven
org.jruby:jruby0.9.2
maven
org.jruby:jruby0.9.8
maven
org.jruby:jruby0.9.9
maven
org.jruby:jruby1.0
maven
org.jruby:jruby1.0.1
maven
org.jruby:jruby1.0.2
maven
org.jruby:jruby1.0.3
maven
org.jruby:jruby1.0RC1
maven
org.jruby:jruby1.0RC2
maven
org.jruby:jruby1.0RC3
maven
org.jruby:jruby1.1
maven
org.jruby:jruby1.1.1
maven
org.jruby:jruby1.1.2
maven
org.jruby:jruby1.1.3
maven
org.jruby:jruby1.1.4
References & sources
- http://www.securityfocus.com/bid/49126vdb-entryx_refsource_BID
- http://www.redhat.com/support/errata/RHSA-2011-1581.htmlvendor-advisoryx_refsource_REDHAT
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69157vdb-entryx_refsource_XF
- http://rhn.redhat.com/errata/RHSA-2012-0070.htmlvendor-advisoryx_refsource_REDHAT
- http://redmine.ruby-lang.org/issues/show/4338x_refsource_MISC
- http://www.openwall.com/lists/oss-security/2011/07/20/1mailing-listx_refsource_MLIST
- https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-5-1-released/x_refsource_CONFIRM
- https://access.redhat.com/errata/RHSA-2018:3729vendor-advisoryx_refsource_REDHAT
- https://usn.ubuntu.com/3626-1/vendor-advisoryx_refsource_UBUNTU
- http://www.securitytracker.com/id/1042004vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/errata/RHSA-2018:3730vendor-advisoryx_refsource_REDHAT
- https://lists.debian.org/debian-lts-announce/2018/04/msg00023.htmlmailing-listx_refsource_MLIST
- https://access.redhat.com/errata/RHSA-2018:3731vendor-advisoryx_refsource_REDHAT
- https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-3-7-released/x_refsource_CONFIRM
- https://www.ruby-lang.org/en/news/2018/03/28/poisoned-nul-byte-dir-cve-2018-8780/x_refsource_CONFIRM
- https://lists.debian.org/debian-lts-announce/2018/07/msg00012.htmlmailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/103739vdb-entryx_refsource_BID
- https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-4-4-released/x_refsource_CONFIRM
- https://www.debian.org/security/2018/dsa-4259vendor-advisoryx_refsource_DEBIAN
- https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-2-10-released/x_refsource_CONFIRM
Linked CVEs
- CVE-2026-27820
A flaw was found in zlib, a Ruby interface for the zlib compression/decompression library.
low - CVE-2024-27282
A flaw was found in Ruby.
— - CVE-2023-28756
A flaw was found in the Time gem and Time library of Ruby.
mediumCVSSv3 5.3 - CVE-2022-28739
A buffer overrun vulnerability was found in Ruby.
highCVSSv3 7.5 - CVE-2021-41819
A flaw was found in Ruby.
— - CVE-2021-31810
Ruby's Net::FTP module trusted the IP address included in the FTP server's response to the PASV command.
— - CVE-2021-28965
A flaw was found in the way the Ruby REXML library parsed XML documents.
— - CVE-2020-25613
An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1.
— - CVE-2019-16254
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting.
— - CVE-2018-8780
It was found that the methods from the Dir class did not properly handle strings containing the NULL byte.
— - CVE-2017-14064
A buffer overflow vulnerability was found in the JSON extension of ruby.
— - CVE-2017-10784
It was found that WEBrick did not sanitize all its log messages.
— - CVE-2015-9096
A SMTP command injection flaw was found in the way Ruby's Net::SMTP module handled CRLF sequences in certain SMTP commands.
— - CVE-2015-7551
The Fiddle::Handle implementation in ext/fiddle/handle.c in Ruby before 2.0.0-p648, 2.1 before 2.1.8, and 2.2 before 2.2.4, as distribute…
— - CVE-2014-8090
The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attac…
— - CVE-2014-8080
The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a deni…
— - CVE-2014-6438
The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service (catastrophic reg…
— - CVE-2014-4975
Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string spe…
— - CVE-2013-1821
lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows remote attackers to cause a denial of service (memory consumption…
— - CVE-2012-5371
Ruby (aka CRuby) 1.9 before 1.9.3-p327 and 2.0 before r37575 computes hash values without properly restricting the ability to trigger has…
— - CVE-2011-4815
Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which all…
— - CVE-2011-3009
Ruby before 1.8.6-p114 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the…
— - CVE-2011-2705
The SecureRandom.random_bytes function in lib/securerandom.rb in Ruby before 1.8.7-p352 and 1.9.x before 1.9.2-p290 relies on PID values…
— - CVE-2011-2686
Ruby before 1.8.7-p352 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the…
—
Show 11 more CVEs
- CVE-2009-5147
DL::dlopen in Ruby 1.8, 1.9.0, 1.9.2, 1.9.3, 2.0.0 before patchlevel 648, and 2.1 before 2.1.8 opens libraries with tainted names.
— - CVE-2008-3905
resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transact…
— - CVE-2008-3657
The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintn…
— - CVE-2008-3656
Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBric…
— - CVE-2008-3655
Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not properly restrict access to cr…
— - CVE-2008-2726
Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 bef…
— - CVE-2008-2725
Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7…
— - CVE-2008-2664
The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0…
— - CVE-2008-2663
Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and…
— - CVE-2008-2662
Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230,…
— - CVE-2008-1891
Directory traversal vulnerability in WEBrick in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.…
—