CVE-2016-2337
CVE-2016-2337
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 6.2%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
06 Jan 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Type confusion exists in _cancel_eval Ruby's TclTkIp class method. Attacker passing different type of object than String as "retval" argument can cause arbitrary code execution.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →