FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-4124

This CVE name corresponds to:

Entered Topic
2009-12-09 ruby -- heap overflow vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-4124
Phase Assigned(20091130)

Description

Heap-based buffer overflow in the rb_str_justify function in string.c in Ruby 1.9.1 before 1.9.1-p376 allows context-dependent attackers to execute arbitrary code via unspecified vectors involving (1) String#ljust, (2) String#center, or (3) String#rjust. NOTE: some of these details are obtained from third party information.

References

Source Reference
CONFIRM http://www.ruby-lang.org/en/news/2009/12/07/heap-overflow-in-string/
BID 37278
OSVDB 60880
SECUNIA 37660
VUPEN ADV-2009-3471
XF ruby-rbstrjustify-bo(54674)