CVE-2014-4975
published 2014-11-15CVE-2014-4975: Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows…
PriorityP427medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
3.89%
89.2th percentile
Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| ruby-lang | ruby | <= 1.9.3 | — |
| ruby-lang | ruby | — | — |
| ruby-lang | ruby | — | — |
| ruby-lang | ruby | — | — |
| ruby-lang | ruby | — | — |
| ruby-lang | ruby | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ruby vulnerabilities
vendor_ubuntu·2014-11-04·CVSS 5.0
CVE-2014-4975 [MEDIUM] Ruby vulnerabilities
Title: Ruby vulnerabilities
Summary: Several security issues were fixed in Ruby.
Will Wood discovered that Ruby incorrectly handled the encodes() function.
An attacker could possibly use this issue to cause Ruby to crash, resulting
in a denial of service, or possibly execute arbitrary code. The default
compiler options for affected releases should reduce the vulnerability to a
denial of service. (CVE-2014-4975)
Willis Vandevanter discovered that Ruby incorrectly handled XML entity
expansion. An attacker could use this flaw to cause Ruby to consume large
amounts of resources, resulting in a denial of service. (CVE-2014-8080)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ruby: off-by-one stack-based buffer overflow in the encodes() function
vendor_redhat·2014-07-09·CVSS 5.0
CVE-2014-4975 [MEDIUM] CWE-193 ruby: off-by-one stack-based buffer overflow in the encodes() function
ruby: off-by-one stack-based buffer overflow in the encodes() function
Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.
Statement: This issue did not affect the versions of ruby as shipped with Red Hat Enterprise Linux 5 and 6.
Package: mingw-ruby (CloudForms Management Engine 5) - Will not fix
Package: ruby193-ruby (CloudForms Management Engine 5) - Will not fix
Package: ruby193-ruby (OpenShift Enterprise 1) - Will not fix
Package: ruby (Red Hat Enterprise Linux 5) - Not affected
Package: ruby (Red Hat Enterprise Linux 6) - Not affected
Package: r
GHSA
GHSA-gxj7-mcpg-jpr6: Off-by-one error in the encodes function in pack
ghsa_unreviewed·2022-05-17
CVE-2014-4975 [MEDIUM] CWE-119 GHSA-gxj7-mcpg-jpr6: Off-by-one error in the encodes function in pack
Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.
OSV
ruby1.8, ruby1.9.1, ruby2.0, ruby2.1 vulnerabilities
osv·2014-11-04·CVSS 5.0
CVE-2014-4975 [MEDIUM] ruby1.8, ruby1.9.1, ruby2.0, ruby2.1 vulnerabilities
ruby1.8, ruby1.9.1, ruby2.0, ruby2.1 vulnerabilities
Will Wood discovered that Ruby incorrectly handled the encodes() function.
An attacker could possibly use this issue to cause Ruby to crash, resulting
in a denial of service, or possibly execute arbitrary code. The default
compiler options for affected releases should reduce the vulnerability to a
denial of service. (CVE-2014-4975)
Willis Vandevanter discovered that Ruby incorrectly handled XML entity
expansion. An attacker could use this flaw to cause Ruby to consume large
amounts of resources, resulting in a denial of service. (CVE-2014-8080)
OSV
CVE-2014-4975: Off-by-one error in the encodes function in pack
osv·2014-07-17·CVSS 5.0
CVE-2014-4975 [MEDIUM] CVE-2014-4975: Off-by-one error in the encodes function in pack
Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-4975 ruby: off-by-one stack-based buffer overflow in the encodes() function [fedora-all]
bugzilla·2014-07-17·CVSS 5.0
CVE-2014-4975 [MEDIUM] CVE-2014-4975 ruby: off-by-one stack-based buffer overflow in the encodes() function [fedora-all]
CVE-2014-4975 ruby: off-by-one stack-based buffer overflow in the encodes() function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2014-4975 ruby: off-by-one stack-based buffer overflow in the encodes() function
bugzilla·2014-07-10·CVSS 5.0
CVE-2014-4975 [MEDIUM] CVE-2014-4975 ruby: off-by-one stack-based buffer overflow in the encodes() function
CVE-2014-4975 ruby: off-by-one stack-based buffer overflow in the encodes() function
A possible stack-based buffer overflow flaw was reported in the Ruby encodes() function from pack.c. From the bug report, this function may be used on data received from a server, and could be triggered remotely.
As the affected stack buffer is a static size on the stack, FORTIFY_SOURCE may help mitigate this issue to only be a denial of service.
The original report suggests older versions (such as 1.9.3) are not affected.
Bug report: https://bugs.ruby-lang.org/issues/10019
CVE request: http://www.openwall.com/lists/oss-security/2014/07/09/13
Discussion:
The proposed patch is not OK, since len can be up to ULONG_MAX big.
The best I could get is:
2.1.2-p168 :015 > ['1'*(2**32)].pack 'm4566666666666
http://advisories.mageia.org/MGASA-2014-0472.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1912.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1913.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1914.htmlhttp://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=revision&revision=46778http://www.debian.org/security/2015/dsa-3157http://www.mandriva.com/security/advisories?name=MDVSA-2015:129http://www.openwall.com/lists/oss-security/2014/07/09/13http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/68474http://www.ubuntu.com/usn/USN-2397-1https://bugs.ruby-lang.org/issues/10019https://bugzilla.redhat.com/show_bug.cgi?id=1118158https://exchange.xforce.ibmcloud.com/vulnerabilities/94706http://advisories.mageia.org/MGASA-2014-0472.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1912.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1913.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1914.htmlhttp://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=revision&revision=46778http://www.debian.org/security/2015/dsa-3157http://www.mandriva.com/security/advisories?name=MDVSA-2015:129http://www.openwall.com/lists/oss-security/2014/07/09/13http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/68474http://www.ubuntu.com/usn/USN-2397-1https://bugs.ruby-lang.org/issues/10019https://bugzilla.redhat.com/show_bug.cgi?id=1118158https://exchange.xforce.ibmcloud.com/vulnerabilities/94706
2014-11-15
Published