VDB
CVE-2014-3916
CVE-2014-3916
PUBLISHED
CVSS 5 MEDIUM
The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string.
EPSS 1.37% · 70.9th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
1.37%
70.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| rubyonrails | rails | 1.9.3, 2.0.0, 2.1.0 |
Timeline
- Nov 16, 2014 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Oct 29, 2022 EPSS Score
- Dec 21, 2022 EPSS Score
- Feb 12, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 6, 2023 EPSS Score
- May 29, 2023 EPSS Score
- Jul 21, 2023 EPSS Score
References
- https://bugs.ruby-lang.org/issues/9709 url
- [oss-security] 20140529 Re: Fwd: [ruby-core:62800] [ruby-trunk - Bug #9709] Large string causes SEGV with x64-mingw32 mailing-list
- [oss-security] 20140527 Fwd: [ruby-core:62800] [ruby-trunk - Bug #9709] Large string causes SEGV with x64-mingw32 mailing-list
- ruby-cve20143916-dos(93505) vdb
- 67705 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2014-3916 advisory