CVE-2014-3916
published 2014-11-16CVE-2014-3916: The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation fault and…
PriorityP418medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.37%
68.4th percentile
The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-252h-69rw-g2rp: The str_buf_cat function in string
ghsa_unreviewed·2022-05-14
CVE-2014-3916 [MEDIUM] GHSA-252h-69rw-g2rp: The str_buf_cat function in string
The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string.
Red Hat
ruby: DoS via long string in str_buf_cat()
vendor_redhat·2014-04-07·CVSS 5.0
CVE-2014-3916 [MEDIUM] CWE-119 ruby: DoS via long string in str_buf_cat()
ruby: DoS via long string in str_buf_cat()
The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string.
Statement: This issue did not affect the versions of ruby as shipped with Red Hat Enterprise Linux 5, 6 or 7 as it only affects the 64-bit Windows platform.
Package: ruby (CloudForms Management Engine 5.2) - Will not fix
Package: ruby (Red Hat Enterprise Linux 5) - Not affected
Package: ruby (Red Hat Enterprise Linux 6) - Not affected
Package: ruby (Red Hat Enterprise Linux 7) - Not affected
No detection rules found.
No public exploits indexed.
http://seclists.org/oss-sec/2014/q2/362http://seclists.org/oss-sec/2014/q2/375http://www.securityfocus.com/bid/67705https://bugs.ruby-lang.org/issues/9709https://exchange.xforce.ibmcloud.com/vulnerabilities/93505http://seclists.org/oss-sec/2014/q2/362http://seclists.org/oss-sec/2014/q2/375http://www.securityfocus.com/bid/67705https://bugs.ruby-lang.org/issues/9709https://exchange.xforce.ibmcloud.com/vulnerabilities/93505
2014-11-16
Published