Description
Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and trunk before revision 43780 allows context-dependent attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a string that is converted to a floating point value, as demonstrated using (1) the to_f method or (2) JSON.parse.
Remediation
References
Related Vulnerabilities
Apache HTTP Server Other Vulnerability (CVE-2002-0843)
WordPress Plugin Velvet Blues Update URLs Unspecified Vulnerability (2.1)
WordPress Plugin Spider FAQ Cross-Site Scripting (1.0.4)
PHP Out-of-bounds Read Vulnerability (CVE-2018-20783)
WordPress Plugin rtMedia for WordPress, BuddyPress and bbPress Unspecified Vulnerability (3.7.18)