RubySec

Providing security resources for the Ruby community

OSVDB-101157 (json): json Gem for Ruby Data Handling Stack Buffer Overflow

ADVISORIES

GEM

json

PATCHED VERSIONS

  • >= 1.1.0

DESCRIPTION

json Gem for Ruby contains an overflow condition that is triggered as user-supplied input is not properly validated when handling specially crafted data. This may allow a remote attacker to cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.

RELATED