Description
In the Ox gem 2.8.0 for Ruby, the process crashes with a segmentation fault when a crafted input is supplied to parse_obj. NOTE: the vendor has stated "Ox should handle the error more gracefully" but has not confirmed a security implication.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-0350 | In the Ox gem 2.8.0 for Ruby, the process crashes with a segmentation fault when a crafted input is supplied to parse_obj. NOTE: the vendor has stated "Ox should handle the error more gracefully" but has not confirmed a security implication. |
Github GHSA |
GHSA-pjj4-w39g-pw54 | Ox gem crashes due to a crafted input |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T18:14:31.774Z
Reserved: 2017-10-27T00:00:00.000Z
Link: CVE-2017-15928
No data.
Status : Modified
Published: 2017-10-27T17:29:00.233
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-15928
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA