CVE-2008-2376 describes an integer overflow vulnerability in the rb_ary_fill function within Ruby versions prior to revision 17756, specifically affecting the Array#fill method. This flaw can be triggered by providing a 'start' argument exceeding ARY_MAX_SIZE, impacting products like Red Hat Fedora 8 and Ruby itself. With a CVSS score of 7.5, this vulnerability is considered high severity, allowing unauthenticated attackers to cause a denial of service (crash) and potentially other unspecified impacts over the network with low attack complexity. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.6.230CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:1.8.6.230:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.