VDB

CVE-2018-10191

CVE-2018-10191 PUBLISHED

In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_GETUPVAR in the presence of deep scope nesting, resulting in a use-after-free. An attacker that can cause Ruby code to be run can use this to possibly execute arbitrary code.

EPSS 1.29% · 80.1th percentile

Risk Scores

EPSS Score
1.29%
80.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSmruby0, 1.1.0+20150906+git1cbbb7e1-1, 1.2.0+20160315+git4f20d58a-1
Ubuntu:18.04:LTSmruby0, 1.4.0-1, 1.3.0-1

Timeline

  • Apr 17, 2018 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • May 7, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›