CVE-2020-15866

Name
CVE-2020-15866
Description
mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrect VM stack handling. It can be triggered via the stack_copy function.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://github.com/mruby/mruby/issues/5042
Mailing List https://lists.debian.org/debian-lts-announce/2022/05/msg00006.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:mruby:mruby:*:*:*:*:*:*:*:* mruby >= None <= 2.1.1
cpe:2.3:a:mruby:mruby:2.1.2:rc:*:*:*:*:*:* mruby == None == 2.1.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
mruby 3.13-community 2.1.2-r0 Jakub Jirutka <jakub@jirutka.cz> fixed