« List of all CVEs

CVE-2016-2337

Published: 1/6/2017 Last updated: 8/5/2024 Reserved: 2/12/2016

Type confusion exists in _cancel_eval Ruby's TclTkIp class method. Attacker passing different type of object than String as "retval" argument can cause arbitrary code execution.

CNA assigner: certcc (37e5125f-f79b-445b-8fad-9564f167944b) Requested by: n/a

Opam packages affected (1)

conf-ruby

Products affected (2)

Product Vendor Version
Ruby Ruby 19.4.0
Tcl/Tk Tcl < publication

References (8)