The CHECK macro in mrbgems/mruby-sprintf/src/sprintf.c in mruby 1.4.1 contains a signed integer overflow, possibly leading to out-of-bounds memory access because the mrb_str_resize function in string.c does not check for a negative length.
| Software | From | Fixed in |
|---|---|---|
| mruby / mruby | 1.4.1 | 1.4.1.x |
| debian / debian_linux | 9.0 | 9.0.x |