Description
ruby-ffi version 1.9.23 and earlier has a DLL loading issue which can be hijacked on Windows OS, when a Symbol is used as DLL name instead of a String This vulnerability appears to have been fixed in v1.9.24 and later.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0350 | ruby-ffi version 1.9.23 and earlier has a DLL loading issue which can be hijacked on Windows OS, when a Symbol is used as DLL name instead of a String This vulnerability appears to have been fixed in v1.9.24 and later. |
Github GHSA |
GHSA-2gw2-8q9w-cw8p | Ruby-ffi has a DLL loading issue |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T12:40:46.796Z
Reserved: 2018-06-05T00:00:00.000Z
Link: CVE-2018-1000201
No data.
Status : Modified
Published: 2018-06-22T18:29:00.217
Modified: 2024-11-21T03:39:55.410
Link: CVE-2018-1000201
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA