First published: Tue Jun 05 2018(Updated: )
The init_copy function in kernel.c in mruby 1.4.1 makes initialize_copy calls for TT_ICLASS objects, which allows attackers to cause a denial of service (mrb_hash_keys uninitialized pointer and application crash) or possibly have unspecified other impact.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mruby Mruby | =1.4.1 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11743 is a vulnerability in mruby 1.4.1 that allows attackers to cause a denial of service or potentially have other impact.
CVE-2018-11743 affects mruby 1.4.1.
The severity of CVE-2018-11743 is critical with a CVSS score of 9.8.
CVE-2018-11743 can be exploited by attackers to cause a denial of service or potentially have other impact.
Yes, there is a fix available for CVE-2018-11743. It is recommended to update to a version of mruby that includes the fix.