Описание
Code injection in dragonfly gem
lib/dragonfly/imagemagickutils.rb in the fog-dragonfly gem 0.8.2 for Ruby allows remote attackers to execute arbitrary commands via unspecified vectors.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2013-5671
- https://github.com/markevans/dragonfly/issues/520
- https://github.com/github/advisory-database/pull/486
- https://web.archive.org/web/20201208033320/http://www.vapid.dhs.org/advisories/fog-dragonfly-0.8.2-cmd-inj.html
- http://seclists.org/fulldisclosure/2013/Sep/18
- http://seclists.org/oss-sec/2013/q3/526
- http://seclists.org/oss-sec/2013/q3/528
Пакеты
Наименование
dragonfly
rubygems
Затронутые версииВерсия исправления
< 1.0.0
1.0.0
Наименование
fog-dragonfly
rubygems
Затронутые версииВерсия исправления
<= 0.9.15
Отсутствует
Связанные уязвимости
nvd
больше 11 лет назад
lib/dragonfly/imagemagickutils.rb in the fog-dragonfly gem 0.8.2 for Ruby allows remote attackers to execute arbitrary commands via unspecified vectors.