10
CVSSv2

CVE-2009-4124

Published: 11/12/2009 Updated: 17/08/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in the rb_str_justify function in string.c in Ruby 1.9.1 prior to 1.9.1-p376 allows context-dependent malicious users to execute arbitrary code via unspecified vectors involving (1) String#ljust, (2) String#center, or (3) String#rjust. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

ruby-lang ruby 1.9.1

Vendor Advisories

Emmanouel Kellinis discovered that Ruby did not properly handle certain string operations An attacker could exploit this issue and possibly execute arbitrary code with application privileges (CVE-2009-4124) ...