8.4

CVE-2015-7551

The Fiddle::Handle implementation in ext/fiddle/handle.c in Ruby before 2.0.0-p648, 2.1 before 2.1.8, and 2.2 before 2.2.4, as distributed in Apple OS X before 10.11.4 and other products, mishandles tainting, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string, related to the DL module and the libffi library.  NOTE: this vulnerability exists because of a CVE-2009-5147 regression.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApplemacOS X Version <= 10.11.3
Ruby-langRuby Version <= 2.0.0-p647
Ruby-langRuby Version2.1.0
Ruby-langRuby Version2.1.1
Ruby-langRuby Version2.1.2
Ruby-langRuby Version2.1.3
Ruby-langRuby Version2.1.4
Ruby-langRuby Version2.1.5
Ruby-langRuby Version2.1.6
Ruby-langRuby Version2.1.7
Ruby-langRuby Version2.2.0
Ruby-langRuby Version2.2.1
Ruby-langRuby Version2.2.2
Ruby-langRuby Version2.2.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.282
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.4 2.5 5.9
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.