Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2014-4975

Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.

  • Published: Nov 15, 2014
  • Updated: Apr 13, 2023
  • CVE: CVE-2014-4975
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:P/I:N/A:N

CWEs:

Software From Fixed in
ruby-lang / ruby 2.0.0 2.0.0.x
ruby-lang / ruby - 1.9.3.x
ruby-lang / ruby 2.0.0-p195 2.0.0-p195.x
ruby-lang / ruby 2.1.1 2.1.1.x
ruby-lang / ruby 2.0 2.0.x
ruby-lang / ruby 2.0.0-preview1 2.0.0-preview1.x
ruby-lang / ruby 2.0.0-p247 2.0.0-p247.x
ruby-lang / ruby 2.0.0-p0 2.0.0-p0.x
ruby-lang / ruby 2.0.0-rc1 2.0.0-rc1.x
ruby-lang / ruby 2.0.0-preview2 2.0.0-preview2.x
ruby-lang / ruby 2.1.2 2.1.2.x
ruby-lang / ruby 2.1 2.1.x
ruby-lang / ruby 2.0.0-rc2 2.0.0-rc2.x
ruby-lang / ruby 2.1-preview1 2.1-preview1.x
redhat / enterprise_linux_desktop 7.0 7.0.x
redhat / enterprise_linux_workstation 7.0 7.0.x
redhat / enterprise_linux_server 7.0 7.0.x
redhat / enterprise_linux_hpc_node 7.0 7.0.x
debian / debian_linux 8.0 8.0.x
debian / debian_linux 7.0 7.0.x
canonical / ubuntu_linux 12.04 12.04.x
canonical / ubuntu_linux 14.10 14.10.x
canonical / ubuntu_linux 14.04 14.04.x