CVE-2017-15928

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
27/10/2017
Last modified:
20/04/2025

Description

In the Ox gem 2.8.0 for Ruby, the process crashes with a segmentation fault when a crafted input is supplied to parse_obj. NOTE: the vendor has stated "Ox should handle the error more gracefully" but has not confirmed a security implication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ox_project:ox:2.8.0:*:*:*:*:ruby:*:*