CVE-2008-2664
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allows context-dependent attackers to trigger memory corruption via unspecified vectors related to alloca, a different issue than CVE-2008-2662, CVE-2008-2663, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.
Metrics
Affected operating systems
linux
debian / debian_linux10.0
linux
debian / debian_linux11.0
linux
debian / debian_linux9.0
linux
ubuntu / ruby2.3xenial
macos
apple / macos
other
fedoraproject / fedora36
other
fedoraproject / fedora37
other
fedoraproject / fedora38
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
bitnami
ruby-min2.6.0
bitnami
ruby-min2.7.0
bitnami
ruby-min3.0.0
bitnami
ruby-min3.1.0
bitnami
ruby-min3.2.0
bitnami
ruby-min3.3.0
bitnami
ruby-min
maven
org.jruby:jruby0.8.3
maven
org.jruby:jruby0.9.1
maven
org.jruby:jruby0.9.2
maven
org.jruby:jruby0.9.8
maven
org.jruby:jruby0.9.9
maven
org.jruby:jruby1.0
maven
org.jruby:jruby1.0.1
maven
org.jruby:jruby1.0.2
maven
org.jruby:jruby1.0.3
maven
org.jruby:jruby1.0RC1
maven
org.jruby:jruby1.0RC2
maven
org.jruby:jruby1.0RC3
maven
org.jruby:jruby1.1
maven
org.jruby:jruby1.1.1
maven
org.jruby:jruby1.1.2
maven
org.jruby:jruby1.1.3
maven
org.jruby:jruby1.1.4
References & sources
- http://www.securityfocus.com/bid/49126vdb-entryx_refsource_BID
- http://www.redhat.com/support/errata/RHSA-2011-1581.htmlvendor-advisoryx_refsource_REDHAT
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69157vdb-entryx_refsource_XF
- http://rhn.redhat.com/errata/RHSA-2012-0070.htmlvendor-advisoryx_refsource_REDHAT
- http://redmine.ruby-lang.org/issues/show/4338x_refsource_MISC
- http://www.openwall.com/lists/oss-security/2011/07/20/1mailing-listx_refsource_MLIST
- https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-5-1-released/x_refsource_CONFIRM
- https://access.redhat.com/errata/RHSA-2018:3729vendor-advisoryx_refsource_REDHAT
- https://usn.ubuntu.com/3626-1/vendor-advisoryx_refsource_UBUNTU
- http://www.securitytracker.com/id/1042004vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/errata/RHSA-2018:3730vendor-advisoryx_refsource_REDHAT
- https://lists.debian.org/debian-lts-announce/2018/04/msg00023.htmlmailing-listx_refsource_MLIST
- https://access.redhat.com/errata/RHSA-2018:3731vendor-advisoryx_refsource_REDHAT
- https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-3-7-released/x_refsource_CONFIRM
- https://www.ruby-lang.org/en/news/2018/03/28/poisoned-nul-byte-dir-cve-2018-8780/x_refsource_CONFIRM
- https://lists.debian.org/debian-lts-announce/2018/07/msg00012.htmlmailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/103739vdb-entryx_refsource_BID
- https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-4-4-released/x_refsource_CONFIRM
- https://www.debian.org/security/2018/dsa-4259vendor-advisoryx_refsource_DEBIAN
- https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-2-10-released/x_refsource_CONFIRM
Linked CVEs
- CVE-2026-27820
A flaw was found in zlib, a Ruby interface for the zlib compression/decompression library.
low - CVE-2024-27282
A flaw was found in Ruby.
— - CVE-2023-28756
A flaw was found in the Time gem and Time library of Ruby.
mediumCVSSv3 5.3 - CVE-2022-28739
A buffer overrun vulnerability was found in Ruby.
highCVSSv3 7.5 - CVE-2021-41819
A flaw was found in Ruby.
— - CVE-2021-31810
Ruby's Net::FTP module trusted the IP address included in the FTP server's response to the PASV command.
— - CVE-2021-28965
A flaw was found in the way the Ruby REXML library parsed XML documents.
— - CVE-2020-25613
An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1.
— - CVE-2019-16254
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting.
— - CVE-2018-8780
It was found that the methods from the Dir class did not properly handle strings containing the NULL byte.
— - CVE-2017-14064
A buffer overflow vulnerability was found in the JSON extension of ruby.
— - CVE-2017-10784
It was found that WEBrick did not sanitize all its log messages.
— - CVE-2015-9096
A SMTP command injection flaw was found in the way Ruby's Net::SMTP module handled CRLF sequences in certain SMTP commands.
— - CVE-2015-7551
The Fiddle::Handle implementation in ext/fiddle/handle.c in Ruby before 2.0.0-p648, 2.1 before 2.1.8, and 2.2 before 2.2.4, as distribute…
— - CVE-2014-8090
The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attac…
— - CVE-2014-8080
The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a deni…
— - CVE-2014-6438
The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service (catastrophic reg…
— - CVE-2014-4975
Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string spe…
— - CVE-2013-1821
lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows remote attackers to cause a denial of service (memory consumption…
— - CVE-2012-5371
Ruby (aka CRuby) 1.9 before 1.9.3-p327 and 2.0 before r37575 computes hash values without properly restricting the ability to trigger has…
— - CVE-2011-4815
Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which all…
— - CVE-2011-3009
Ruby before 1.8.6-p114 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the…
— - CVE-2011-2705
The SecureRandom.random_bytes function in lib/securerandom.rb in Ruby before 1.8.7-p352 and 1.9.x before 1.9.2-p290 relies on PID values…
— - CVE-2011-2686
Ruby before 1.8.7-p352 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the…
—
Show 11 more CVEs
- CVE-2011-0188
The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Ruby 1.9.2-p136 and earlier, as used on Apple Mac OS X before 10.6.7 a…
— - CVE-2009-5147
DL::dlopen in Ruby 1.8, 1.9.0, 1.9.2, 1.9.3, 2.0.0 before patchlevel 648, and 2.1 before 2.1.8 opens libraries with tainted names.
— - CVE-2008-3905
resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transact…
— - CVE-2008-3657
The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintn…
— - CVE-2008-3656
Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBric…
— - CVE-2008-3655
Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not properly restrict access to cr…
— - CVE-2008-2726
Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 bef…
— - CVE-2008-2725
Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7…
— - CVE-2008-2663
Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and…
— - CVE-2008-2662
Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230,…
— - CVE-2008-1891
Directory traversal vulnerability in WEBrick in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.…
—