Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 RubyGems

Buffer overrun in CGI.escape_html

GHSA-5cqm-crxm-6qpv · CVE-2021-41816

Published · Modified

Description

A buffer overrun vulnerability was discovered in CGI.escape_html. This can lead to a buffer overflow when a user passes a very large string (> 700 MB) to CGI.escape_html on a platform where long type takes 4 bytes, typically, Windows.

Ready to move

Start Securing

Free, no credit card | First findings in minutes