CVE-2018-12248

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
12/06/2018
Last modified:
03/10/2019

Description

An issue was discovered in mruby 1.4.1. There is a heap-based buffer over-read associated with OP_ENTER because mrbgems/mruby-fiber/src/fiber.c does not extend the stack in cases of many arguments to fiber.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mruby:mruby:1.4.1:*:*:*:*:*:*:*