Denial of Service Vulnerability in mruby Affected by Uninitialized Pointer
CVE-2018-11743

9.8CRITICAL

Key Information:

Vendor

Mruby

Status
Vendor
CVE Published:
5 June 2018

What is CVE-2018-11743?

The init_copy function in kernel.c of mruby version 1.4.1 contains a vulnerability that can be exploited to initiate an application crash. Attackers can leverage uninitialized pointers in TT_ICLASS objects during initialize_copy calls, leading to potential denial of service. This flaw not only disrupts normal operation but could also result in other unspecified adverse effects on the application. It's crucial for developers and users to remain vigilant and apply necessary updates to maintain application stability and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.