CVE-2018-3759
Last modified
CVE-2018-3759 is a vulnerability of currently unknown severity. private_address_check ruby gem before 0.5.0 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition due to the address the socket uses not being checked. DNS entries with a TTL of 0 can trigger this case where the initial resolution is a public address but the subsequent resolution is a private address.. EPSS estimates a 0.69% chance of exploitation in the next 30 days.
Description
private_address_check ruby gem before 0.5.0 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition due to the address the socket uses not being checked. DNS entries with a TTL of 0 can trigger this case where the initial resolution is a public address but the subsequent resolution is a private address.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Private Address Check Project | Private Address Check | < 0.5.0 |
References
- https://github.com/jtdowney/private_address_check/commit/4068228187db87fea7577f7020099399772bb147Patch, Third Party Advisory
- https://github.com/jtdowney/private_address_check/commit/4068228187db87fea7577f7020099399772bb147Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-3759?
How severe is CVE-2018-3759?
How do I fix CVE-2018-3759?
Are you affected by CVE-2018-3759?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
