CVE-2013-5671
EPSS 2.2%Code injection in dragonfly gem
發布日:2017/10/24修改日:2024/12/8
描述
`lib/dragonfly/imagemagickutils.rb` in the fog-dragonfly gem 0.8.2 for Ruby allows remote attackers to execute arbitrary commands via unspecified vectors.
受影響套件(2)
- RubyGems/dragonflyfrom 0, < 1.0.0
- RubyGems/fog-dragonflyfrom 0, <= 0.9.15
參考連結(8)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2013-5671
- PATCHhttps://github.com/markevans/dragonfly
- WEBhttp://seclists.org/fulldisclosure/2013/Sep/18
- WEBhttp://seclists.org/oss-sec/2013/q3/526
- WEBhttp://seclists.org/oss-sec/2013/q3/528
- WEBhttps://github.com/github/advisory-database/pull/486
- WEBhttps://github.com/markevans/dragonfly/issues/520
- WEBhttps://web.archive.org/web/20201208033320/http://www.vapid.dhs.org/advisories/fog-dragonfly-0.8.2-cmd-inj.html