RubySec

Providing security resources for the Ruby community

CVE-2013-1947 (kelredd-pruview): kelredd-pruview Gem for Ruby /lib/pruview/document.rb File Name Shell Metacharacter Injection Arbitrary Command Execution

ADVISORIES

GEM

kelredd-pruview

SEVERITY

CVSS v2: 9.3 (High)

PATCHED VERSIONS

None.

DESCRIPTION

kelredd-pruview Gem for Ruby contains a flaw in /lib/pruview/document.rb. The issue is triggered during the handling of a specially crafted file name that contains injected shell metacharacters. This may allow a context-dependent attacker to potentially execute arbitrary commands.