Description
The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Ruby 1.9.2-p136 and earlier, as used on Apple Mac OS X before 10.6.7 and other platforms, does not properly allocate memory, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving creation of a large BigDecimal value within a 64-bit process, related to an "integer truncation issue."
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2006-1870 Vulnerability (CVE-2006-1870)
Atlassian Jira CVE-2012-2926 Vulnerability (CVE-2012-2926)
WordPress Plugin MX Time Zone Clocks Cross-Site Scripting (3.4)
WordPress Plugin MailArchiver Cross-Site Scripting (2.10.1)
Apache Tomcat Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-5351)