CVE-2018-10199

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
18/04/2018
Last modified:
22/05/2018

Description

In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_copy(). An attacker that can cause Ruby code to be run can possibly use this to execute arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mruby:mruby:*:*:*:*:*:*:*:* 1.4.0 (including)