CVE-2016-2337
CVE-2016-2337
Type confusion exists in _cancel_eval Ruby's TclTkIp class method. Attacker passing different type of object than String as "retval" argument can cause arbitrary code execution.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →