Bugzilla – Bug 1198288
VUL-0: CVE-2022-1276: mruby: Out-of-bounds Read in mrb_get_args in mruby prior to 3.2
Last modified: 2022-04-26 19:17:59 UTC
CVE-2022-1276 Out-of-bounds Read in mrb_get_args in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-1276 https://github.com/mruby/mruby/commit/c8c083cb750606b2da81582cd8e43b442bb143e6 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1276 http://www.cvedetails.com/cve/CVE-2022-1276/ https://huntr.dev/bounties/6ea041d1-e2aa-472c-bf3e-da5fa8726c25
Affects: - openSUSE:Factory/mruby 3.0.0
Could not reproduce, probably not affected 3.0 but only git. > % mruby POC > trace (most recent call last): > ./POC:1: Integer cannot be converted to String (TypeError)