Vulnerability CVE-2018-16396: Information

Description

An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats.

Severity: HIGH (8.1) Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Published: Nov. 16, 2018
Modified: Oct. 3, 2019

Fixed packages

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:ruby-lang:ruby:2.6.0:preview1:*:*:*:*:*:*

      cpe:2.3:a:ruby-lang:ruby:2.6.0:preview2:*:*:*:*:*:*

      cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*
      Start including
      2.3.0
      End including
      2.3.7

      cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*
      Start including
      2.4.0
      End including
      2.4.4

      cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*
      Start including
      2.5.0
      End including
      2.5.1

      Configuration 2

      cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:o:redhat:enterprise_linux:7.4:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux:7.5:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux:7.6:*:*:*:*:*:*:*