CVE-2008-2663
Last modified
CVE-2008-2663 is a vulnerability of currently unknown severity. Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors, a different issue than CVE-2008-2662, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. EPSS estimates a 4.46% chance of exploitation in the next 30 days.
Description
Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors, a different issue than CVE-2008-2662, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ruby-Lang | Ruby | <= 1.8.4 |
| Ruby-Lang | Ruby | > 1.8.5, < 1.8.5.231 |
| Ruby-Lang | Ruby | >= 1.8.6, < 1.8.6.230 |
| Ruby-Lang | Ruby | >= 1.8.7, < 1.8.7.22 |
| Debian | Debian Linux | 4.0 |
| Canonical | Ubuntu Linux | 6.06 |
| Canonical | Ubuntu Linux | 7.04 |
| Canonical | Ubuntu Linux | 7.10 |
| Canonical | Ubuntu Linux | 8.04 |
References
- http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.htmlThird Party Advisory
- http://secunia.com/advisories/30802Third Party Advisory
- http://secunia.com/advisories/30831Third Party Advisory
- http://secunia.com/advisories/30867Third Party Advisory
- http://secunia.com/advisories/30875Third Party Advisory
- http://secunia.com/advisories/30894Third Party Advisory
- http://secunia.com/advisories/31062Third Party Advisory
- http://secunia.com/advisories/31090Third Party Advisory
- http://secunia.com/advisories/31181Third Party Advisory
- http://secunia.com/advisories/31256Third Party Advisory
- http://secunia.com/advisories/31687Third Party Advisory
- http://secunia.com/advisories/33178Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200812-17.xmlThird Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.429562Mailing List, Third Party Advisory
- http://support.apple.com/kb/HT2163Third Party Advisory
- http://weblog.rubyonrails.org/2008/6/21/multiple-ruby-security-vulnerabilitiesThird Party Advisory
- http://www.debian.org/security/2008/dsa-1612Third Party Advisory
- http://www.debian.org/security/2008/dsa-1618Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:140Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:141Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:142Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0561.htmlThird Party Advisory
- http://www.ruby-forum.com/topic/157034Third Party Advisory
- http://www.ruby-lang.org/en/news/2008/06/20/arbitrary-code-execution-vulnerabilities/Patch, Vendor Advisory
- http://www.rubyinside.com/june-2008-ruby-security-vulnerabilities-927.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/493688/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/29903Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020347Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-621-1Third Party Advisory
- http://www.vupen.com/english/advisories/2008/1907/referencesThird Party Advisory
- http://www.vupen.com/english/advisories/2008/1981/referencesThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43346Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-2626Broken Link
- https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00937.htmlThird Party Advisory
- http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.htmlThird Party Advisory
- http://secunia.com/advisories/30802Third Party Advisory
- http://secunia.com/advisories/30831Third Party Advisory
- http://secunia.com/advisories/30867Third Party Advisory
- http://secunia.com/advisories/30875Third Party Advisory
- http://secunia.com/advisories/30894Third Party Advisory
- http://secunia.com/advisories/31062Third Party Advisory
- http://secunia.com/advisories/31090Third Party Advisory
- http://secunia.com/advisories/31181Third Party Advisory
- http://secunia.com/advisories/31256Third Party Advisory
- http://secunia.com/advisories/31687Third Party Advisory
- http://secunia.com/advisories/33178Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200812-17.xmlThird Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.429562Mailing List, Third Party Advisory
- http://support.apple.com/kb/HT2163Third Party Advisory
- http://weblog.rubyonrails.org/2008/6/21/multiple-ruby-security-vulnerabilitiesThird Party Advisory
- http://www.debian.org/security/2008/dsa-1612Third Party Advisory
- http://www.debian.org/security/2008/dsa-1618Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:140Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:141Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:142Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0561.htmlThird Party Advisory
- http://www.ruby-forum.com/topic/157034Third Party Advisory
- http://www.ruby-lang.org/en/news/2008/06/20/arbitrary-code-execution-vulnerabilities/Patch, Vendor Advisory
- http://www.rubyinside.com/june-2008-ruby-security-vulnerabilities-927.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/493688/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/29903Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020347Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-621-1Third Party Advisory
- http://www.vupen.com/english/advisories/2008/1907/referencesThird Party Advisory
- http://www.vupen.com/english/advisories/2008/1981/referencesThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43346Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-2626Broken Link
- https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00937.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-2663?
How severe is CVE-2008-2663?
How do I fix CVE-2008-2663?
Are you affected by CVE-2008-2663?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
