PT-2013-3483 · Ruby · Md2Pdf

Published

2013-04-25

·

Updated

2017-10-24

·

CVE-2013-1948

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions md2pdf gem version 0.0.1
Description The issue allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename. This is possible due to a flaw in the converter.rb file within the md2pdf gem for Ruby.
Recommendations For md2pdf gem version 0.0.1, consider restricting the use of the converter.rb file until a patch is available, and avoid using filenames that contain shell metacharacters to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2013-1948
GHSA-99CH-8MVP-G7M5

Affected Products

Md2Pdf