CVE-2008-2664
Last modified
CVE-2008-2664 is a vulnerability of currently unknown severity. The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allows context-dependent attackers to trigger memory corruption via unspecified vectors related to alloca, a different issue than CVE-2008-2662, CVE-2008-2663, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. EPSS estimates a 4.28% chance of exploitation in the next 30 days.
Description
The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allows context-dependent attackers to trigger memory corruption via unspecified vectors related to alloca, a different issue than CVE-2008-2662, CVE-2008-2663, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ruby-Lang | Ruby | <= 1.8.4 |
| Ruby-Lang | Ruby | > 1.8.5, < 1.8.5.231 |
| Ruby-Lang | Ruby | >= 1.8.6, < 1.8.6.230 |
| Ruby-Lang | Ruby | >= 1.8.7, < 1.8.7.22 |
| Ruby-Lang | Ruby | >= 1.9.0, < 1.9.0.2 |
| Debian | Debian Linux | 4.0 |
| Canonical | Ubuntu Linux | 6.06 |
| Canonical | Ubuntu Linux | 7.04 |
| Canonical | Ubuntu Linux | 7.10 |
| Canonical | Ubuntu Linux | 8.04 |
References
- http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.htmlThird Party Advisory
- http://secunia.com/advisories/30802Third Party Advisory
- http://secunia.com/advisories/30831Third Party Advisory
- http://secunia.com/advisories/30867Third Party Advisory
- http://secunia.com/advisories/30875Third Party Advisory
- http://secunia.com/advisories/30894Third Party Advisory
- http://secunia.com/advisories/31062Third Party Advisory
- http://secunia.com/advisories/31090Third Party Advisory
- http://secunia.com/advisories/31181Third Party Advisory
- http://secunia.com/advisories/31256Third Party Advisory
- http://secunia.com/advisories/31687Third Party Advisory
- http://secunia.com/advisories/33178Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200812-17.xmlThird Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.429562Mailing List, Third Party Advisory
- http://support.apple.com/kb/HT2163Third Party Advisory
- http://weblog.rubyonrails.org/2008/6/21/multiple-ruby-security-vulnerabilitiesThird Party Advisory
- http://www.debian.org/security/2008/dsa-1612Third Party Advisory
- http://www.debian.org/security/2008/dsa-1618Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:140Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:141Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:142Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0561.htmlThird Party Advisory
- http://www.ruby-forum.com/topic/157034Third Party Advisory
- http://www.ruby-lang.org/en/news/2008/06/20/arbitrary-code-execution-vulnerabilities/Patch, Vendor Advisory
- http://www.rubyinside.com/june-2008-ruby-security-vulnerabilities-927.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/493688/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/29903Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020347Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-621-1Third Party Advisory
- http://www.vupen.com/english/advisories/2008/1907/referencesThird Party Advisory
- http://www.vupen.com/english/advisories/2008/1981/referencesThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43348Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-2626Broken Link
- https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00937.htmlThird Party Advisory
- http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.htmlThird Party Advisory
- http://secunia.com/advisories/30802Third Party Advisory
- http://secunia.com/advisories/30831Third Party Advisory
- http://secunia.com/advisories/30867Third Party Advisory
- http://secunia.com/advisories/30875Third Party Advisory
- http://secunia.com/advisories/30894Third Party Advisory
- http://secunia.com/advisories/31062Third Party Advisory
- http://secunia.com/advisories/31090Third Party Advisory
- http://secunia.com/advisories/31181Third Party Advisory
- http://secunia.com/advisories/31256Third Party Advisory
- http://secunia.com/advisories/31687Third Party Advisory
- http://secunia.com/advisories/33178Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200812-17.xmlThird Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.429562Mailing List, Third Party Advisory
- http://support.apple.com/kb/HT2163Third Party Advisory
- http://weblog.rubyonrails.org/2008/6/21/multiple-ruby-security-vulnerabilitiesThird Party Advisory
- http://www.debian.org/security/2008/dsa-1612Third Party Advisory
- http://www.debian.org/security/2008/dsa-1618Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:140Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:141Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:142Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0561.htmlThird Party Advisory
- http://www.ruby-forum.com/topic/157034Third Party Advisory
- http://www.ruby-lang.org/en/news/2008/06/20/arbitrary-code-execution-vulnerabilities/Patch, Vendor Advisory
- http://www.rubyinside.com/june-2008-ruby-security-vulnerabilities-927.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/493688/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/29903Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020347Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-621-1Third Party Advisory
- http://www.vupen.com/english/advisories/2008/1907/referencesThird Party Advisory
- http://www.vupen.com/english/advisories/2008/1981/referencesThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43348Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-2626Broken Link
- https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00937.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-2664?
How severe is CVE-2008-2664?
How do I fix CVE-2008-2664?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-2651SQL injection vulnerability in the Joomla! Bulletin Board (a…
- CVE-2008-2652Multiple SQL injection vulnerabilities in catalog.php in SME…
- CVE-2008-2654Off-by-one error in the read_client function in webhttpd.c i…
- CVE-2008-2660Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2008-2662Multiple integer overflows in the rb_str_buf_append function…
- CVE-2008-2663Multiple integer overflows in the rb_ary_store function in R…
- CVE-2008-2665Directory traversal vulnerability in the posix_access functi…
- CVE-2008-2666Multiple directory traversal vulnerabilities in PHP 5.2.6 an…
- CVE-2008-2667SQL injection vulnerability in the Courier Authentication Li…
- CVE-2008-2668Multiple cross-site scripting (XSS) vulnerabilities in yBlog…
- CVE-2008-2669Multiple SQL injection vulnerabilities in yBlog 0.2.2.2 allo…
- CVE-2008-2670Multiple SQL injection vulnerabilities in index.php in Insan…
Are you affected by CVE-2008-2664?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
