{"id":"GHSA-5gxp-c379-pj42","summary":"ccsv Double Free vulnerability","details":"The foreach function in `ext/ccsv.c` in Ccsv 1.1.0 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact via a crafted file.","aliases":["CVE-2017-15364"],"modified":"2023-11-08T03:58:56.900068Z","published":"2022-05-17T00:29:07Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-01-27T00:53:20Z","nvd_published_at":"2017-10-15T19:29:00Z","cwe_ids":["CWE-415"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-15364"},{"type":"WEB","url":"https://github.com/evan/ccsv/issues/15"},{"type":"PACKAGE","url":"https://github.com/evan/ccsv"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ccsv/CVE-2017-15364.yml"}],"affected":[{"package":{"name":"ccsv","ecosystem":"RubyGems","purl":"pkg:gem/ccsv"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.1.0"}]}],"versions":["0.0.1","0.0.2","0.1","0.1.1","0.1.2","1.0.1","1.0.4","1.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5gxp-c379-pj42/GHSA-5gxp-c379-pj42.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}