Description
Type confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface. Attacker passing different type of object than this assumed by developers can cause arbitrary code execution.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-3420 | Type confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface. Attacker passing different type of object than this assumed by developers can cause arbitrary code execution. |
References
History
No history.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-05T23:24:48.901Z
Reserved: 2016-02-12T00:00:00.000Z
Link: CVE-2016-2336
No data.
Status : Modified
Published: 2017-01-06T21:59:00.447
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-2336
OpenCVE Enrichment
No data.
Weaknesses
EUVD