NA

CVE-2024-27282

Published: 14/05/2024 Updated: 14/05/2024

Vulnerability Summary

An issue exists in Ruby 3.x up to and including 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.

Vulnerability Trend

Vendor Advisories

Debian Bug report logs - #1069968 ruby32: CVE-2024-27282 Package: src:ruby32; Maintainer for src:ruby32 is Debian Ruby Team <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 27 Apr 2024 20:27:02 UTC Severity: grave Tags: security, upstream Foun ...