← Vulnerability feed

Vulnerability record · CVE-2017-14033 · published 19 September 2017

CVE-2017-14033: Ruby-lang ruby memory buffer overflow vulnerability

Ruby Lang · Ruby

The decode method in the OpenSSL::ASN1 module in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows attackers to cause a denial of service (interpreter crash) via a crafted string.

7.5 CVSS 3.0 High EPSS 7.7% · top 5.6% CWE-119 · Memory buffer overflow
7.5CVSS 3.0 base score, v2 5.0
7.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
24References
17 Jun 2026Last modified by NVD

Description

The decode method in the OpenSSL::ASN1 module in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows attackers to cause a denial of service (interpreter crash) via a crafted string.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/100868 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039363 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1042004
https://access.redhat.com/errata/RHSA-2018:0378
https://access.redhat.com/errata/RHSA-2018:0583
https://access.redhat.com/errata/RHSA-2018:0585
https://lists.debian.org/debian-lts-announce/2018/07/msg00012.html
https://security.gentoo.org/glsa/201710-18
https://www.debian.org/security/2017/dsa-4031
https://www.ruby-lang.org/en/news/2017/09/14/openssl-asn1-buffer-underrun-cve-2017-14033/ MitigationVendor Advisory
https://www.ruby-lang.org/en/news/2017/09/14/ruby-2-2-8-released/ PatchRelease NotesVendor Advisory
https://www.ruby-lang.org/en/news/2017/09/14/ruby-2-3-5-released/ PatchRelease NotesVendor Advisory
http://www.securityfocus.com/bid/100868 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039363 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1042004
https://access.redhat.com/errata/RHSA-2018:0378
https://access.redhat.com/errata/RHSA-2018:0583
https://access.redhat.com/errata/RHSA-2018:0585
https://lists.debian.org/debian-lts-announce/2018/07/msg00012.html
https://security.gentoo.org/glsa/201710-18
https://www.debian.org/security/2017/dsa-4031
https://www.ruby-lang.org/en/news/2017/09/14/openssl-asn1-buffer-underrun-cve-2017-14033/ MitigationVendor Advisory
https://www.ruby-lang.org/en/news/2017/09/14/ruby-2-2-8-released/ PatchRelease NotesVendor Advisory
https://www.ruby-lang.org/en/news/2017/09/14/ruby-2-3-5-released/ PatchRelease NotesVendor Advisory

Track CVE-2017-14033 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-4124Ruby-lang ruby memory buffer overflow vulnerabilityHeap-based buffer overflow in the rb_str_justify function in string.c in Ruby 1.9.1 before 1.9.1-p376 allows context-dependent attackers to execute a…EPSS 3.9%10.0CVE-2008-2662Ruby-lang ruby vulnerabilityMultiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 befor…EPSS 4.3%10.0CVE-2008-2663Ruby-lang ruby integer overflow vulnerabilityMultiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before…EPSS 4.5%9.8CVE-2016-2338Ruby-lang ruby out-of-bounds write vulnerabilityAn exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function he…EPSS 4.7%9.8CVE-2022-28738Ruby-lang ruby double free vulnerabilityA double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untruste…EPSS 2.9%9.8CVE-2011-4121Ruby-lang ruby inadequate encryption strength vulnerabilityThe OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private…EPSS 2.5%9.8CVE-2018-16395Ruby-lang openssl vulnerabilityAn issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. When tw…EPSS 11%9.8CVE-2017-17790Ruby-lang ruby injection vulnerabilityThe lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by…EPSS 5.9%

Source: NIST National Vulnerability Database (record CVE-2017-14033), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.