The parser_yyerror function in the UTF-8 parser in Ruby 2.4.1 allows attackers to cause a denial of service (invalid write or read) or possibly have unspecified other impact via a crafted Ruby script, related to the parser_tokadd_utf8 function in parse.y. NOTE: this might have security relevance as a bypass of a $SAFE protection mechanism.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-07-19T21:00:00Z

Updated: 2024-09-16T17:15:26.973Z

Reserved: 2017-07-19T00:00:00Z

Link: CVE-2017-11465

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-07-19T21:29:00.243

Modified: 2017-07-25T18:15:44.743

Link: CVE-2017-11465

cve-icon Redhat

Severity : Low

Publid Date: 2017-07-13T00:00:00Z

Links: CVE-2017-11465 - Bugzilla