CVE-2008-2662
Last modified
CVE-2008-2662 is a vulnerability of currently unknown severity. Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors that trigger memory corruption, a different issue than CVE-2008-2663, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. EPSS estimates a 4.26% chance of exploitation in the next 30 days.
Description
Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors that trigger memory corruption, a different issue than CVE-2008-2663, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. This CVE description should be regarded as authoritative, although it is likely to change.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ruby-Lang | Ruby | <= 1.8.4 |
| Ruby-Lang | Ruby | > 1.8.5, < 1.8.5.231 |
| Ruby-Lang | Ruby | >= 1.8.6, < 1.8.6.230 |
| Ruby-Lang | Ruby | >= 1.8.7, < 1.8.7.22 |
| Ruby-Lang | Ruby | >= 1.9.0, < 1.9.0.2 |
| Debian | Debian Linux | 4.0 |
| Canonical | Ubuntu Linux | 6.06 |
| Canonical | Ubuntu Linux | 7.04 |
| Canonical | Ubuntu Linux | 7.10 |
| Canonical | Ubuntu Linux | 8.04 |
References
- http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.htmlThird Party Advisory
- http://secunia.com/advisories/30802Third Party Advisory
- http://secunia.com/advisories/30831Third Party Advisory
- http://secunia.com/advisories/30867Third Party Advisory
- http://secunia.com/advisories/30875Third Party Advisory
- http://secunia.com/advisories/30894Third Party Advisory
- http://secunia.com/advisories/31062Third Party Advisory
- http://secunia.com/advisories/31181Third Party Advisory
- http://secunia.com/advisories/31256Third Party Advisory
- http://secunia.com/advisories/31687Third Party Advisory
- http://secunia.com/advisories/33178Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200812-17.xmlThird Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.429562Mailing List, Third Party Advisory
- http://support.apple.com/kb/HT2163Third Party Advisory
- http://weblog.rubyonrails.org/2008/6/21/multiple-ruby-security-vulnerabilitiesThird Party Advisory
- http://www.debian.org/security/2008/dsa-1612Third Party Advisory
- http://www.debian.org/security/2008/dsa-1618Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:140Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:141Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:142Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0561.htmlThird Party Advisory
- http://www.ruby-forum.com/topic/157034Third Party Advisory
- http://www.ruby-lang.org/en/news/2008/06/20/arbitrary-code-execution-vulnerabilities/Patch, Vendor Advisory
- http://www.rubyinside.com/june-2008-ruby-security-vulnerabilities-927.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/493688/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/29903Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020347Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-621-1Third Party Advisory
- http://www.vupen.com/english/advisories/2008/1907/referencesThird Party Advisory
- http://www.vupen.com/english/advisories/2008/1981/referencesThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43345Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-2626Broken Link
- https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00937.htmlThird Party Advisory
- http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.htmlThird Party Advisory
- http://secunia.com/advisories/30802Third Party Advisory
- http://secunia.com/advisories/30831Third Party Advisory
- http://secunia.com/advisories/30867Third Party Advisory
- http://secunia.com/advisories/30875Third Party Advisory
- http://secunia.com/advisories/30894Third Party Advisory
- http://secunia.com/advisories/31062Third Party Advisory
- http://secunia.com/advisories/31181Third Party Advisory
- http://secunia.com/advisories/31256Third Party Advisory
- http://secunia.com/advisories/31687Third Party Advisory
- http://secunia.com/advisories/33178Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200812-17.xmlThird Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.429562Mailing List, Third Party Advisory
- http://support.apple.com/kb/HT2163Third Party Advisory
- http://weblog.rubyonrails.org/2008/6/21/multiple-ruby-security-vulnerabilitiesThird Party Advisory
- http://www.debian.org/security/2008/dsa-1612Third Party Advisory
- http://www.debian.org/security/2008/dsa-1618Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:140Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:141Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:142Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0561.htmlThird Party Advisory
- http://www.ruby-forum.com/topic/157034Third Party Advisory
- http://www.ruby-lang.org/en/news/2008/06/20/arbitrary-code-execution-vulnerabilities/Patch, Vendor Advisory
- http://www.rubyinside.com/june-2008-ruby-security-vulnerabilities-927.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/493688/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/29903Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020347Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-621-1Third Party Advisory
- http://www.vupen.com/english/advisories/2008/1907/referencesThird Party Advisory
- http://www.vupen.com/english/advisories/2008/1981/referencesThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43345Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-2626Broken Link
- https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00937.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-2662?
How severe is CVE-2008-2662?
How do I fix CVE-2008-2662?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-2649Multiple PHP remote file inclusion vulnerabilities in Deskto…
- CVE-2008-2650Directory traversal vulnerability in cmsimple/cms.php in CMS…
- CVE-2008-2651SQL injection vulnerability in the Joomla! Bulletin Board (a…
- CVE-2008-2652Multiple SQL injection vulnerabilities in catalog.php in SME…
- CVE-2008-2654Off-by-one error in the read_client function in webhttpd.c i…
- CVE-2008-2660Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2008-2663Multiple integer overflows in the rb_ary_store function in R…
- CVE-2008-2664The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 …
- CVE-2008-2665Directory traversal vulnerability in the posix_access functi…
- CVE-2008-2666Multiple directory traversal vulnerabilities in PHP 5.2.6 an…
- CVE-2008-2667SQL injection vulnerability in the Courier Authentication Li…
- CVE-2008-2668Multiple cross-site scripting (XSS) vulnerabilities in yBlog…
Are you affected by CVE-2008-2662?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
