Oval Definition:oval:com.ubuntu.precise:def:20144975000
Revision Date:2014-11-15Version:1
Title:CVE-2014-4975 on Ubuntu 12.04 LTS (precise) - low.
Description:Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2014-4975
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND Package Information
  • NOT While related to the CVE in some way, the 'ruby1.8' package in precise is not affected (note: '1.8.7.352-2ubuntu1.4').
  • OR The 'ruby1.9.1' package in precise was vulnerable but has been fixed (note: '1.9.3.0-1ubuntu2.9').
  • BACK