Candidate: CVE-2018-10191 PublicDate: 2018-04-17 21:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10191 https://github.com/mruby/mruby/commit/1905091634a6a2925c911484434448e568330626 https://github.com/mruby/mruby/issues/3995 Description: In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_GETUPVAR in the presence of deep scope nesting, resulting in a use-after-free. An attacker that can cause Ruby code to be run can use this to possibly execute arbitrary code. Ubuntu-Description: Notes: Bugs: https://bugs.launchpad.net/ubuntu/+source/mruby/+bug/1763905 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_mruby: upstream_mruby: released (1.4.1) precise/esm_mruby: DNE trusty_mruby: ignored (reached end-of-life) trusty/esm_mruby: DNE (trusty was needs-triage) xenial_mruby: ignored (end of standard support, was needs-triage) artful_mruby: ignored (reached end-of-life) bionic_mruby: needs-triage cosmic_mruby: not-affected (1.4.1-2) disco_mruby: not-affected (1.4.1-2) eoan_mruby: not-affected (1.4.1-2) focal_mruby: not-affected (1.4.1-2) groovy_mruby: not-affected (1.4.1-2) hirsute_mruby: not-affected (1.4.1-2) impish_mruby: not-affected (1.4.1-2) jammy_mruby: not-affected (1.4.1-2) devel_mruby: not-affected (1.4.1-2)