CVE-2018-12249: Null Pointer Dereference
An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrbclassreal because "class BasicObject" is not properly supported in class.c.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-12249?
The severity of CVE-2018-12249 is high, with a severity keyword of 'high' and a severity value of 7.5.
What is the affected software for CVE-2018-12249?
The affected software for CVE-2018-12249 is Mruby 1.4.1 and Debian Debian Linux 9.0.
What is the description of CVE-2018-12249?
CVE-2018-12249 is an issue discovered in mruby 1.4.1 where there is a NULL pointer dereference in mrb_class_real due to improper support for 'class BasicObject' in class.c.
How can I fix CVE-2018-12249?
To fix CVE-2018-12249, it is recommended to update to a version of mruby that includes the fix or apply the relevant patch provided by the vendor.
Where can I find more information about CVE-2018-12249?
More information about CVE-2018-12249 can be found in the references: [GitHub Commit](https://github.com/mruby/mruby/commit/faa4eaf6803bd11669bc324b4c34e7162286bfa3), [GitHub Issue](https://github.com/mruby/mruby/issues/4037), [Debian LTS Announcement](https://lists.debian.org/debian-lts-announce/2022/05/msg00006.html).