Intel

AIKIDO-2024-10428

stringio is vulnerable to Out-of-bounds Write

Out-of-bounds Write Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

85

High Risk

This Affects:

rubystringio
0.0.2 - 3.1.1
Fixed in 3.1.2

TL;DR

An undisclosed vulnerability was detected in stringio. The update addresses a bug where StringIO#ungetc and StringIO#ungetbyte methods could potentially use unknown memory, leading to unexpected behavior or memory corruption.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

stringio is vulnerable to Out-of-bounds Write in versions 0.0.2 - 3.1.1.

How to fix this

Upgrade the stringio library to the patch version.