Back

CRITICAL

ruby: WIN32OLE ole_invoke and ole_query_interface type confusion vulnerabilities

Published Jan 6, 2017

Description

Type confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface. Attacker passing different type of object than this assumed by developers can cause arbitrary code execution.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of ruby as shipped with Red Hat Enterprise Linux or Red Hat Software Collections as they did not include support for OLE.

Metrics

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published Jan 6, 2017
Updated Aug 5, 2024
Reserved Feb 12, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jun 14, 2016