PT-2013-3464 · Ruby · Ldoce Gem

Published

2013-04-03

·

Updated

2017-10-24

·

CVE-2013-1911

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ldoce gem version 0.0.2
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters in an mp3 URL or file name. This is possible due to a flaw in the lib/ldoce/word.rb file of the ldoce gem for Ruby.
Recommendations For ldoce gem version 0.0.2, consider restricting the use of the lib/ldoce/word.rb file until a patch is available, and avoid using shell metacharacters in mp3 URLs or file names to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-1911
GHSA-G266-3CRH-H7GJ

Affected Products

Ldoce Gem