Ruby Floating Point Parsing Heap Buffer Overflow Vulnerability

Bugtraq ID: 63873
Class: Boundary Condition Error
CVE: CVE-2013-4164
Remote: Yes
Local: No
Published: Nov 22 2013 12:00AM
Updated: Apr 13 2015 09:19PM
Credit: Charlie Somerville
Vulnerable: Yukihiro Matsumoto Ruby 1.9.3 dev
Yukihiro Matsumoto Ruby 1.9.2 RC2
Yukihiro Matsumoto Ruby 1.9.2 P180
Yukihiro Matsumoto Ruby 1.9.2 P136
Yukihiro Matsumoto Ruby 1.9.2 P0
Yukihiro Matsumoto Ruby 1.9.2 -rc1
Yukihiro Matsumoto Ruby 1.9.1 P431
Yukihiro Matsumoto Ruby 1.9.1 -p429
Yukihiro Matsumoto Ruby 1.9.1 -p376
Yukihiro Matsumoto Ruby 1.9.1
Yukihiro Matsumoto Ruby 1.9 -2
Yukihiro Matsumoto Ruby 1.9 -1
Yukihiro Matsumoto Ruby 1.9
Yukihiro Matsumoto Ruby 1.8.7 -p72
Yukihiro Matsumoto Ruby 1.8.7 -p71
Yukihiro Matsumoto Ruby 1.8.7 -p22
Yukihiro Matsumoto Ruby 1.8.7 -p21
Yukihiro Matsumoto Ruby 1.8.7
Yukihiro Matsumoto Ruby 1.8.6 -p287
Yukihiro Matsumoto Ruby 1.8.6 -p286
Yukihiro Matsumoto Ruby 1.8.6 -p230
Yukihiro Matsumoto Ruby 1.8.6 -p229
Yukihiro Matsumoto Ruby 1.8.6 -p114
Yukihiro Matsumoto Ruby 1.8.6
Yukihiro Matsumoto Ruby 1.8.5 -p231
Yukihiro Matsumoto Ruby 1.8.5 -p230
Yukihiro Matsumoto Ruby 1.8.5 -p2
Yukihiro Matsumoto Ruby 1.8.5 -p115
Yukihiro Matsumoto Ruby 1.8.5
Yukihiro Matsumoto Ruby 1.8.4
Yukihiro Matsumoto Ruby 1.8.3
Yukihiro Matsumoto Ruby 1.8.2 pre4
+ Gentoo Linux
Yukihiro Matsumoto Ruby 1.8.2 pre3
+ Gentoo Linux
Yukihiro Matsumoto Ruby 1.8.2 pre2
Yukihiro Matsumoto Ruby 1.8.2 pre1
Yukihiro Matsumoto Ruby 1.8.2
Yukihiro Matsumoto Ruby 1.8.1
+ Redhat Fedora Core3
+ Redhat Fedora Core2
Yukihiro Matsumoto Ruby 1.8
Yukihiro Matsumoto Ruby 2.1.0-preview1
Yukihiro Matsumoto Ruby 2.0.0-p247
Yukihiro Matsumoto Ruby 2.0.0-p195
Yukihiro Matsumoto Ruby 2.0
Yukihiro Matsumoto Ruby 1.9.3-p448
Yukihiro Matsumoto Ruby 1.9.3-p426
Yukihiro Matsumoto Ruby 1.9.3-p392
Yukihiro Matsumoto Ruby 1.9.3-p327
Yukihiro Matsumoto Ruby 1.9.3-p0
Yukihiro Matsumoto Ruby 1.9.2 pre3
Yukihiro Matsumoto Ruby 1.9.1-p430
Yukihiro Matsumoto Ruby 1.9.1-p378
Yukihiro Matsumoto Ruby 1.9.0-3
Yukihiro Matsumoto Ruby 1.8.8dev
Yukihiro Matsumoto Ruby 1.8.7-p374
Yukihiro Matsumoto Ruby 1.8.7-P357
Yukihiro Matsumoto Ruby 1.8.7-P352
Yukihiro Matsumoto Ruby 1.8.7-p334
Yukihiro Matsumoto Ruby 1.8.7-p330
Yukihiro Matsumoto Ruby 1.8.7-p302
Yukihiro Matsumoto Ruby 1.8.7-p299
Yukihiro Matsumoto Ruby 1.8.7-p249
Yukihiro Matsumoto Ruby 1.8.7-p248
Yukihiro Matsumoto Ruby 1.8.7-p173
Yukihiro Matsumoto Ruby 1.8.7-p160
Yukihiro Matsumoto Ruby 1.8.6-p420
Yukihiro Matsumoto Ruby 1.8.6-p399
Yukihiro Matsumoto Ruby 1.8.6-p388
Yukihiro Matsumoto Ruby 1.8.6-p383
Yukihiro Matsumoto Ruby 1.8.6-p369
Yukihiro Matsumoto Ruby 1.8.6-p368
Ubuntu Ubuntu Linux 13.10
Ubuntu Ubuntu Linux 13.04
Ubuntu Ubuntu Linux 12.10
Ubuntu Ubuntu Linux 12.04
SuSE SUSE Linux Enterprise Software Development Kit 11 SP3
+ Linux kernel 2.6.5
SuSE SUSE Linux Enterprise Server 11 SP3 for VMware
SuSE SUSE Linux Enterprise Server 11 SP3
SuSE SUSE Linux Enterprise Server 11 SP2 for VMware
SuSE SUSE Linux Enterprise Server 11 SP2
+ Linux kernel 2.6.5
SuSE Suse Linux Enterprise Desktop 11 SP3
+ Linux kernel 2.6.5
SuSE Suse Linux Enterprise Desktop 11 SP2
SuSE Studio Onsite 1.3
SuSE Linux Enterprise Software Development Kit 11 SP2
SuSE Lifecycle Management Server 1.3
Slackware Linux 14.1
Slackware Linux 14.0
Slackware Linux 13.37
Slackware Linux 13.1
S.u.S.E. openSUSE 13.1
S.u.S.E. openSUSE 12.3
S.u.S.E. openSUSE 12.2
Redhat Software Collections 1 for RHEL 6 0
Redhat OpenStack 3.0
Redhat Enterprise Linux Workstation 6
Redhat Enterprise Linux Server EUS 6.4.z
Redhat Enterprise Linux Server EUS 6.3.z
Redhat Enterprise Linux Server EUS 6.2.z
Redhat Enterprise Linux Server AUS 6.4
Redhat Enterprise Linux Server AUS 6.2
Redhat Enterprise Linux Server 6
Redhat Enterprise Linux HPC Node 6
Redhat Enterprise Linux High Availability EUS 6.4.z
Redhat Enterprise Linux Desktop 6
Redhat CloudForms 3.0
Puppetlabs Puppet Enterprise 3.1
Puppetlabs Puppet Enterprise 2.8.3
Puppetlabs Puppet Enterprise 2.8.2
Puppetlabs Puppet Enterprise 2.8.0
Oracle Solaris 11.2
Oracle Enterprise Linux 6.2
Oracle Enterprise Linux 6
Mandriva Business Server 1 X86 64
Mandriva Business Server 1
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
IBM Security Network Protection XGS 5100 5.1.1
IBM Security Network Protection XGS 5100 5.1
IBM Security Network Protection XGS 5.1.2
Gentoo Linux
Debian Linux 6.0 sparc
Debian Linux 6.0 s/390
Debian Linux 6.0 powerpc
Debian Linux 6.0 mips
Debian Linux 6.0 ia-64
Debian Linux 6.0 ia-32
Debian Linux 6.0 arm
Debian Linux 6.0 amd64
Apple OS X Mavericks 10.9.2
Apple Mac OS X Server 10.7.5
Apple Mac OS X Server 10.6.3
Apple Mac OS X Server 10.5.3
Apple Mac OS X Server 10.4.3
Apple Mac OS X Server 10.3.9
Apple Mac OS X Server 10.3.8
Apple Mac OS X Server 10.3.7
Apple Mac OS X Server 10.3.6
Apple Mac OS X Server 10.3.5
Apple Mac OS X Server 10.3.4
Apple Mac OS X Server 10.3.3
Apple Mac OS X Server 10.3.2
Apple Mac OS X Server 10.3.1
Apple Mac OS X Server 10.3
Apple Mac OS X Server 10.2.3
Apple Mac OS X Server 10.1.3
Apple Mac OS X Server 3.0
Apple Mac OS X Server 2.0
Apple Mac OS X Server 10.7.3
Apple Mac OS X 10.8.5
Apple Mac OS X 10.7.5
Apple Mac OS X 10.9.2
Not Vulnerable: Yukihiro Matsumoto Ruby 2.1.0-preview2
Yukihiro Matsumoto Ruby 2.0.0-p353
Yukihiro Matsumoto Ruby 1.9.3-p484
Puppetlabs Puppet Enterprise 3.1.1
Puppetlabs Puppet Enterprise 2.8.4
Apple OS X Mavericks 10.9.3
Apple Mac OS X Server 3.1.2
Apple Mac OS X Server 4.0


 

Privacy Statement
Copyright 2010, SecurityFocus