CVE-2008-2664 describes a memory corruption vulnerability in the rb_str_format function of various Ruby versions (1.8.4 and earlier, 1.8.5 before p231, 1.8.6 before p230, 1.8.7 before p22, and 1.9.0 before 1.9.0-2). This flaw, related to alloca, allows context-dependent attackers to trigger memory corruption and affects products like Canonical, Debian, and Ruby-lang distributions of Ruby and Linux. With a CVSS score of 7.8 (High), this vulnerability has a network-based attack vector, low attack complexity, and can lead to complete system availability compromise (A:C) without requiring authentication. There is no impact on confidentiality or integrity. Despite its severity, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.8.4CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* | ||
> 1.8.5, < 1.8.5.231CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* | ||
>= 1.8.6, < 1.8.6.230CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* | ||
>= 1.8.7, < 1.8.7.22CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* | ||
>= 1.9.0, < 1.9.0.2CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.