RubySec

Providing security resources for the Ruby community

OSVDB-108579 (lynx): lynx Gem for Ruby lib/lynx/pipe/run.rb Remote Command Execution

lynx Gem for Ruby lib/lynx/pipe/run.rb Remote Command Execution

Published: June 30, 2014

SECURITY IDENTIFIERS

GEM

lynx

PATCHED VERSIONS

None available.

DESCRIPTION

lynx Gem for Ruby contains a flaw in lib/lynx/pipe/run.rb that may allow a remote attacker to execute arbitrary commands.

RELATED