Vulnerabilities > CVE-2018-12247 - NULL Pointer Dereference vulnerability in Mruby 1.4.1

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
mruby
CWE-476

Summary

An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class, related to certain .clone usage, because mrb_obj_clone in kernel.c copies flags other than the MRB_FLAG_IS_FROZEN flag (e.g., the embedded flag).

Vulnerable Configurations

Part Description Count
Application
Mruby
1

Common Weakness Enumeration (CWE)