suse · CVE-2018-16396

Quick triage

Priority: medium 公開: 2021-05-30 14:16:25 UTC Updated: 2026-04-17 15:18:06 UTC

参照: Official suse advisory, NVD, CVE.org · CVE 詳細

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-16396 severity moderate: SUSE including 309 source package names (2.17-17.3:libruby2_5-2_5-2.5.5-4.3.1, 2.17-17.3:ruby2.5-2.5.5-4.3.1, …), 1022 product×package rows across 252 product lines (Container bci/ruby, Container suse/rmt-server, … (252 product lines)): Fixed 842, Known Affected 157, Known Not Affected 23.

Description:

An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats.

cvelogic Threat Intelligence