PT-2016-1114 · Ruby · Colorscore

Dirk Zittersteyn

+1

·

Published

2016-01-08

·

Updated

2018-08-15

·

CVE-2015-7541

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions colorscore gem versions prior to 0.0.5
Description The issue is related to the initialize method in the Histogram class, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in the image path, colors, or depth variable. This is due to a lack of input data sanitization measures. The exploitation of this issue can enable a remote attacker to execute arbitrary code.
Recommendations For versions prior to 0.0.5, update to version 0.0.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of the image path, colors, and depth variables in the initialize method of the Histogram class to minimize the risk of exploitation.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00359
CVE-2015-7541
GHSA-73QW-WW62-M54X
GHSA-9WCM-RRVH-QJC8

Affected Products

Colorscore