CVE-2017-9527: Use After Free
Published Jun 11, 2017
·Updated
The markcontextstack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of service (heap-based use-after-free and application crash) or possibly have unspecified other impact via a crafted .rb file.
Affected Software
2 affected components
mruby mruby<=1.2.0
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
Jun 11, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9527?
CVE-2017-9527 has a high severity rating as it allows for denial of service through heap-based use-after-free vulnerabilities.
2
How do I fix CVE-2017-9527?
To fix CVE-2017-9527, upgrade to mruby version 1.3.0 or later, which addresses the vulnerability.
3
What systems are affected by CVE-2017-9527?
CVE-2017-9527 affects mruby versions up to and including 1.2.0 and Debian Linux 9.0.
4
What types of impacts can CVE-2017-9527 lead to?
CVE-2017-9527 can lead to denial of service, application crashes, and potentially unspecified other impacts.
5
Is CVE-2017-9527 a remote attack vector?
CVE-2017-9527 can potentially be exploited through crafted .rb files, which may be delivered remotely.