{"id":"CVE-2017-11465","details":"The parser_yyerror function in the UTF-8 parser in Ruby 2.4.1 allows attackers to cause a denial of service (invalid write or read) or possibly have unspecified other impact via a crafted Ruby script, related to the parser_tokadd_utf8 function in parse.y. NOTE: this might have security relevance as a bypass of a $SAFE protection mechanism.","modified":"2026-07-08T12:05:46.487695Z","published":"2017-07-19T21:29:00.243Z","references":[{"type":"FIX","url":"https://bugs.ruby-lang.org/issues/13742"},{"type":"FIX","url":"https://bugs.ruby-lang.org/projects/ruby-trunk/repository/revisions/59344"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ruby/ruby","events":[{"introduced":"820605ba3c10b9f4dafc4e5d6e09765b8b31cbea"},{"last_affected":"820605ba3c10b9f4dafc4e5d6e09765b8b31cbea"}],"database_specific":{"cpe":"cpe:2.3:a:ruby-lang:ruby:2.4.1:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.4.1"},{"last_affected":"2.4.1"}],"source":"CPE_STRING"}}],"versions":["2.4.1","v2_4_1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-11465.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}