CVE-2018-1000201

NameCVE-2018-1000201
Descriptionruby-ffi version 1.9.23 and earlier has a DLL loading issue which can be hijacked on Windows OS, when a Symbol is used as DLL name instead of a String This vulnerability appears to have been fixed in v1.9.24 and later.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ruby-ffi (PTS)buster1.9.10debian-1fixed
bullseye1.12.2+dfsg-2fixed
bookworm1.15.5+dfsg-1fixed
sid, trixie1.16.3+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ruby-ffisource(unstable)(not affected)

Notes

- ruby-ffi <not-affected> (Windows-specific)

Search for package or bug name: Reporting problems