Record summary

CVE-2016-2337 has a selected CVSS score of 9.8 (critical).

Description

Type confusion exists in _cancel_eval Ruby's TclTkIp class method. Attacker passing different type of object than String as "retval" argument can cause arbitrary code execution.

Description source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List2.3.0 devaffected
2.2.2affected
CVE List8.6 or lateraffected

References

5