CVE-2014-3916: Medium severity ruby on rails vulnerability
Published Nov 16, 2014
·Updated
The strbufcat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string.
Affected Software
3 affected components
rubyonrails Rails=1.9.3
rubyonrails Rails=2.0.0
rubyonrails Rails=2.1.0
Event History
Nov 16, 2014
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3916?
CVE-2014-3916 has a severity rating that may lead to denial of service through a segmentation fault.
2
How do I fix CVE-2014-3916?
To fix CVE-2014-3916, upgrade to a patched version of Ruby that is not affected by this vulnerability.
3
What versions of Ruby are affected by CVE-2014-3916?
CVE-2014-3916 affects Ruby versions 1.9.3, 2.0.0, and 2.1.0.
4
What type of attack does CVE-2014-3916 enable?
CVE-2014-3916 enables context-dependent attackers to perform a denial of service attack by causing a crash.
5
Is CVE-2014-3916 a code execution vulnerability?
No, CVE-2014-3916 is not a code execution vulnerability but rather a denial of service vulnerability.