CVE-2018-10199
published 2018-04-18CVE-2018-10199: In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_copy(). An attacker that can cause Ruby…
PriorityP345critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.34%
81.7th percentile
In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_copy(). An attacker that can cause Ruby code to be run can possibly use this to execute arbitrary code.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mruby | < mruby 1.4.0+20180418+git54905e98-1 (bookworm) | mruby 1.4.0+20180418+git54905e98-1 (bookworm) |
| mruby | mruby | <= 1.4.0 | — |
| mruby | mruby | >= 0 < 1.4.0+20180418+git54905e98-1 | 1.4.0+20180418+git54905e98-1 |
| mruby | mruby | >= 0 < 1.4.0+20180418+git54905e98-1 | 1.4.0+20180418+git54905e98-1 |
| mruby | mruby | >= 0 < 1.4.0+20180418+git54905e98-1 | 1.4.0+20180418+git54905e98-1 |
| mruby | mruby | >= 0 < 1.4.0+20180418+git54905e98-1 | 1.4.0+20180418+git54905e98-1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2018-10199: mruby - In versions of mruby up to and including 1.4.0, a use-after-free vulnerability e...
vendor_debian·2018·CVSS 9.8
CVE-2018-10199 [CRITICAL] CVE-2018-10199: mruby - In versions of mruby up to and including 1.4.0, a use-after-free vulnerability e...
In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_copy(). An attacker that can cause Ruby code to be run can possibly use this to execute arbitrary code.
Scope: local
bookworm: resolved (fixed in 1.4.0+20180418+git54905e98-1)
bullseye: resolved (fixed in 1.4.0+20180418+git54905e98-1)
forky: resolved (fixed in 1.4.0+20180418+git54905e98-1)
sid: resolved (fixed in 1.4.0+20180418+git54905e98-1)
trixie: resolved (fixed in 1.4.0+20180418+git54905e98-1)
GHSA
GHSA-xpq9-m45f-g29q: In versions of mruby up to and including 1
ghsa_unreviewed·2022-05-14
CVE-2018-10199 [CRITICAL] CWE-416 GHSA-xpq9-m45f-g29q: In versions of mruby up to and including 1
In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_copy(). An attacker that can cause Ruby code to be run can possibly use this to execute arbitrary code.
OSV
CVE-2018-10199: In versions of mruby up to and including 1
osv·2018-04-18·CVSS 9.8
CVE-2018-10199 [CRITICAL] CVE-2018-10199: In versions of mruby up to and including 1
In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_copy(). An attacker that can cause Ruby code to be run can possibly use this to execute arbitrary code.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-04-18
Published