CVE Database
/

CVE-2014-4975

Back to search

CVE-2014-4975

Published: Nov 15, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2014:1912
vendor-advisory
x_refsource_REDHAT
68474
vdb-entry
x_refsource_BID
RHSA-2014:1913
vendor-advisory
x_refsource_REDHAT
DSA-3157
vendor-advisory
x_refsource_DEBIAN
USN-2397-1
vendor-advisory
x_refsource_UBUNTU
MDVSA-2015:129
vendor-advisory
x_refsource_MANDRIVA
RHSA-2014:1914
vendor-advisory
x_refsource_REDHAT
ruby-cve20144975-bo(94706)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now