VDB
GCVE-VVD-MAGEIA-2017-371
GCVE-VVD-MAGEIA-2017-371
Advisory Published
If a malicious format string which contains a precious specifier (*) is
passed and a huge minus value is also passed to the specifier, buffer
underrun may be caused. In such situation, the result may contains heap,
or the Ruby interpreter may crash (CVE-2017-0898).
If a malicious string is passed to the decode method of OpenSSL::ASN1,
buffer underrun may be caused and the Ruby interpreter may crash
(CVE-2017-14033).
The generate method of JSON module optionally accepts an instance of
JSON::Ext::Generator::State class. If a malicious instance is passed,
the result may include contents of heap (CVE-2017-14064).
When using the Basic authentication of WEBrick, clients can pass an
arbitrary string as the user name. WEBrick outputs the passed user name
intact to its log, then an attacker can inject malicious escape
sequences to the log and dangerous control characters may be executed on
a victim’s terminal emulator (CVE-2017-10784).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | ruby-json | 0 (affected), 1.8.1-3.1.mga5 (unaffected) | — |
| Mageia | ruby | 0 (affected), 2.0.0.p648-1.5.mga5 (unaffected) | — |
| Mageia | ruby | 0 (affected), 2.2.8-1.mga6 (unaffected) | — |
| Mageia | ruby-json | 0 (affected), 1.8.3-3.1.mga6 (unaffected) | — |
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.