suse · CVE-2017-0898

Quick triage

Priority: medium Published: 2021-05-30 13:50:02 UTC Updated: 2026-04-18 15:49:29 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2017-0898 severity moderate: SUSE including 24 source package names (libruby2_1-2_1-2.1.9-19.3.2, ruby, …), 177 product×package rows across 67 product lines (HPE Helion OpenStack 8, Image SLES12-SP5-Azure-BYOS, … (67 product lines)): Fixed 140, Known Not Affected 32, Will Not Fix 5.

Description:

Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such situation can lead to a buffer overrun, resulting in a heap memory corruption or an information disclosure from the heap.

cvelogic Threat Intelligence