91233vdb entry
http://www.securityfocus.com/bid/91233 CVE-2016-2337
CRITICAL
Record summary
CVE-2016-2337 has a selected CVSS score of 9.8 (critical).
Description
Type confusion exists in _cancel_eval Ruby's TclTkIp class method. Attacker passing different type of object than String as "retval" argument can cause arbitrary code execution.
Description source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 2.3.0 dev | affected | |
| 2.2.2 | affected | ||
Tcl/TkBrowse Tcl / Tcl/Tk | CVE List | 8.6 or later | affected |
References
5talosintelligence.com
http://www.talosintelligence.com/reports/TALOS-2016-0031 [debian-lts-announce] 20180827 [SECURITY] [DLA 1480-1] ruby2.1 security updatemailing list
https://lists.debian.org/debian-lts-announce/2018/08/msg00028.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-2337 GLSA-201710-18Vendor advisory
https://security.gentoo.org/glsa/201710-18