PT-2016-1114 · Ruby · Colorscore
Dirk Zittersteyn
+1
·
Published
2016-01-08
·
Updated
2018-08-15
·
CVE-2015-7541
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
colorscore gem versions prior to 0.0.5
Description
The issue is related to the initialize method in the Histogram class, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in the
image path, colors, or depth variable. This is due to a lack of input data sanitization measures. The exploitation of this issue can enable a remote attacker to execute arbitrary code.Recommendations
For versions prior to 0.0.5, update to version 0.0.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
image path, colors, and depth variables in the initialize method of the Histogram class to minimize the risk of exploitation.Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Colorscore