CVE-2008-2376

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
09/07/2008
Last modified:
09/04/2025

Description

Integer overflow in the rb_ary_fill function in array.c in Ruby before revision 17756 allows context-dependent attackers to cause a denial of service (crash) or possibly have unspecified other impact via a call to the Array#fill method with a start (aka beg) argument greater than ARY_MAX_SIZE. NOTE: this issue exists because of an incomplete fix for other closely related integer overflows.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:redhat:fedora_8:1.8.6.230:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6.230:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools