Ruby Other Vulnerability - CVE-2016-2337
Type confusion exists in _cancel_eval Ruby39s TclTkIp class method. Attacker passing different type of object than String as quotretvalquot argument can cause arbitrary code execution.
Type confusion exists in _cancel_eval Ruby39s TclTkIp class method. Attacker passing different type of object than String as quotretvalquot argument can cause arbitrary code execution.