Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2008-2662

Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors that trigger memory corruption, a different issue than CVE-2008-2663, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. This CVE description should be regarded as authoritative, although it is likely to change.

  • Published: Jun 24, 2008
  • Updated: Apr 13, 2023
  • CVE: CVE-2008-2662
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 10
  • AV:N/AC:L/Au:N/C:C/I:C/A:C

CWEs:

Software From Fixed in
ruby-lang / ruby - 1.8.4.x
ruby-lang / ruby 1.8.5.x 1.8.5.231
ruby-lang / ruby 1.8.6 1.8.6.230
ruby-lang / ruby 1.8.7 1.8.7.22
ruby-lang / ruby 1.9.0 1.9.0.2
debian / debian_linux 4.0 4.0.x
canonical / ubuntu_linux 6.06 6.06.x
canonical / ubuntu_linux 7.04 7.04.x
canonical / ubuntu_linux 7.10 7.10.x
canonical / ubuntu_linux 8.04 8.04.x