Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary code execution if being exploited.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://huntr.dev/bounties/23b6f0a9-64f5-421e-a55f-b5b7a671f301 | third party advisory exploit |
https://github.com/mruby/mruby/commit/a4d97934d51cb88954cc49161dc1d151f64afb6b | third party advisory patch |