Buffer underflow in sprintf
R
Ruby
Submitted None
Actions:
Reported by
haquaman
Vulnerability Details
Technical details and impact analysis
Hi,
So I found this in mruby as part of the shopify-scripts program, and I notice that my patch also landed upstream in ruby as well. Shame on me for not checking ruby as well!
Wondered if it counted for a bounty here as well?
https://github.com/mruby/mruby/issues/3347 <- issue that shopify guys opened on my behalf.
https://github.com/ruby/ruby/commit/0854193a684acc2b3a13ab28091a4397000c8822 <- commit landed upstream.
https://hackerone.com/reports/191328 (still open so not public) is the original report of mine.
Let me know if you need anything more.
Cheers,
Hugh
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$500.00
Submitted
Weakness
Memory Corruption - Generic