Loading HuntDB...

GHSA-2gw2-8q9w-cw8p

GitHub Security Advisory

Ruby-ffi has a DLL loading issue

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

ruby-ffi version 1.9.23 and earlier has a DLL loading issue which can be hijacked on Windows OS, when a Symbol is used as DLL name instead of a String This vulnerability appears to have been fixed in v1.9.24 and later.

Affected Packages

RubyGems ffi
Affected versions: 0 (fixed in 1.9.24)

Related CVEs

Key Information

GHSA ID
GHSA-2gw2-8q9w-cw8p
Published
August 31, 2018 2:55 PM
Last Modified
January 25, 2023 10:55 PM
CVSS Score
7.5 /10
Primary Ecosystem
RubyGems
Primary Package
ffi
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 3, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.