RubySec

Providing security resources for the Ruby community

OSVDB-101157 (json): json Gem for Ruby Data Handling Stack Buffer Overflow

json Gem for Ruby Data Handling Stack Buffer Overflow

Published: May 21, 2007

SECURITY IDENTIFIERS

GEM

json

PATCHED VERSIONS

>= 1.1.0

DESCRIPTION

json Gem for Ruby contains an overflow condition that is triggered as user-supplied input is not properly validated when handling specially crafted data. This may allow a remote attacker to cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.

RELATED