Описание
flash_tool Gem for Ruby File Download Handling Arbitrary Command Execution
flash_tool Gem for Ruby contains a flaw that is triggered during the handling of downloaded files that contain shell characters. With a specially crafted file, a context-dependent attacker can execute arbitrary commands.
Пакеты
Наименование
flash_tool
rubygems
Затронутые версииВерсия исправления
<= 0.6.0
Отсутствует
Связанные уязвимости
CVSS3: 9.8
nvd
около 2 лет назад
The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file.