[FREEBSD:2CE1A2F1-0177-11EF-A45E-08002784C58D] ruby -- Arbitrary memory address read vulnerability with Regex search

Affected Packages 4
CVEs 1

sp2ip reports:

    If attacker-supplied data is provided to the Ruby regex
    compiler, it is possible to extract arbitrary heap data
    relative to the start of the text, including pointers and
    sensitive strings.
Package Affected Version
pkg:freebsd/ruby33 < 3.3.1,1
pkg:freebsd/ruby32 < 3.2.4,1
pkg:freebsd/ruby31 < 3.1.5,1
pkg:freebsd/ruby < 3.1.5,1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:freebsd/ruby33 ruby33 < 3.3.1,1
Affected pkg:freebsd/ruby32 ruby32 < 3.2.4,1
Affected pkg:freebsd/ruby31 ruby31 < 3.1.5,1
Affected pkg:freebsd/ruby ruby < 3.1.5,1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...