CVE-2017-0898

CVE-2017-0898

Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a leakage of its heap by the malicious specification of the format of sprintf method. If a script allows to accept any format from the outside, there is a risk to be spied the contents of the heap.

Source: CVE-2017-0898

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다