erb is vulnerable to Integer Overflow
65
Medium Risk
Affected versions of this package are vulnerable to an integer overflow in the Util.html_escape method. The code stores segment lengths in a 16-bit integer (uint16_t), so a long unescaped segment (≥ 65,536 bytes) can wrap the length value, causing incorrect memcpy() sizes and a buffer overrun. This may lead to memory corruption and a crash (denial of service), and in the worst case could enable further exploitation.
You are affected if you are using a version that falls within the vulnerable range.
erb is vulnerable to Integer Overflow in versions 5.1.0 - 5.1.0.
Upgrade the erb library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant