talosintelligence.com
http://www.talosintelligence.com/reports/TALOS-2016-0029 CVE-2016-2336
CRITICAL
Record summary
CVE-2016-2336 has a selected CVSS score of 9.8 (critical).
Description
Type confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface. Attacker passing different type of object than this assumed by developers can cause arbitrary code execution.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 2.3.0 dev | affected | |
| 2.2.2 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-2336