CVE-2014-4975

Impact:
Low
Public Date:
2014-07-09
CWE:
CWE-193->CWE-121
Bugzilla:
1118158: CVE-2014-4975 ruby: off-by-one stack-based buffer overflow in the encodes() function

The MITRE CVE dictionary describes this issue as:

Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.

Find out more about CVE-2014-4975 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue did not affect the versions of ruby as shipped with Red Hat Enterprise Linux 5 and 6.

CVSS v2 metrics

Base Score 2.6
Base Metrics AV:N/AC:H/Au:N/C:N/I:N/A:P
Access Vector Network
Access Complexity High
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 (ruby200-ruby) RHSA-2014:1914 2014-11-26
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7 (ruby200-ruby) RHSA-2014:1914 2014-11-26
Red Hat Enterprise Linux 7 (ruby) RHSA-2014:1912 2014-11-26
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 (ruby193-ruby) RHSA-2014:1913 2014-11-26
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7 (ruby193-ruby) RHSA-2014:1913 2014-11-26

Affected Packages State

Platform Package State
Red Hat Subscription Asset Manager 1 ruby193-ruby Will not fix
Red Hat Satellite 6 rubygem-rake Will not fix
Red Hat OpenShift Enterprise 1 ruby193-ruby Will not fix
Red Hat Enterprise Linux OpenStack Platform 4.0 ruby193-ruby Will not fix
Red Hat Enterprise Linux OpenStack Platform 3.0 ruby193-ruby Will not fix
Red Hat Enterprise Linux 6 ruby Not affected
Red Hat Enterprise Linux 5 ruby Not affected

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.