PT-2013-3483 · Ruby · Md2Pdf

Publicado

2013-04-25

·

Atualizado

2017-10-24

·

CVE-2013-1948

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions md2pdf gem version 0.0.1
Description The issue allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename. This is possible due to a flaw in the converter.rb file within the md2pdf gem for Ruby.
Recommendations For md2pdf gem version 0.0.1, consider restricting the use of the converter.rb file until a patch is available, and avoid using filenames that contain shell metacharacters to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2013-1948
GHSA-99CH-8MVP-G7M5

Produtos afetados

Md2Pdf