Ox gem crashes due to a crafted input
High severity
GitHub Reviewed
Published
Nov 21, 2017
to the GitHub Advisory Database
•
Updated Aug 28, 2023
Description
Published to the GitHub Advisory Database
Nov 21, 2017
Reviewed
Jun 16, 2020
Last updated
Aug 28, 2023
In the Ox gem 2.8.0 for Ruby, the process crashes with a segmentation fault when a crafted input is supplied to
parse_obj
. NOTE: the vendor has stated "Ox should handle the error more gracefully" but has not confirmed a security implication.References