mruby bigint.c udiv floating point comparison with incorrect operator
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.9epss 0.5%
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A flaw has been found in mruby 3.1.0. Affected is the function udiv of the file bigint.c. Executing a manipulation can lead to floating point comparison with incorrect operator. It is possible to launch the attack remotely. The exploit has been published and may be used. It is best practice to apply a patch to resolve this issue.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
n/a · mrubypublic PoCs found — 1
cve_referencehuntr.com/bounties/5a5092df-1699-4497-a8b2-38318bce0c4eunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.