suse · CVE-2018-8778

Quick triage

Priority: medium Published: 2021-05-30 14:11:54 UTC Updated: 2026-04-17 15:29:23 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-8778 severity moderate: SUSE including 300 source package names (2.17-17.3:libruby2_5-2_5-2.5.5-4.3.1, 2.17-17.3:ruby2.5-2.5.5-4.3.1, …), 1000 product×package rows across 244 product lines (Container bci/ruby, Container suse/rmt-server, … (244 product lines)): Fixed 842, Known Affected 157, Known Not Affected 1.

Description:

In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker controlling the unpacking format (similar to format string vulnerabilities) can trigger a buffer under-read in the String#unpack method, resulting in a massive and controlled information disclosure.

cvelogic Threat Intelligence