In the Ox gem 2.8.0 for Ruby, the process crashes with a segmentation fault when a crafted input is supplied to parse_obj. NOTE: the vendor has stated "Ox should handle the error more gracefully" but has not confirmed a security implication.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "2.1.1-2+deb9u1build0.16.04.1", "binary_name": "ruby-ox" }, { "binary_version": "2.1.1-2+deb9u1build0.16.04.1", "binary_name": "ruby-ox-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "2.8.2-1build2", "binary_name": "ruby-ox" }, { "binary_version": "2.8.2-1build2", "binary_name": "ruby-ox-dbgsym" } ] }