lynx Gem for Ruby lib/lynx/pipe/run.rb Remote Command Execution
Published: June 30, 2014
SECURITY IDENTIFIERS
- OSVDB: OSVDB-108579
- Vendor Advisory: https://www.openwall.com/lists/oss-security/2014/07/07/23
GEM
PATCHED VERSIONS
None available.
DESCRIPTION
lynx Gem for Ruby contains a flaw in lib/lynx/pipe/run.rb that may allow a remote attacker to execute arbitrary commands.
