ADVISORIES
- OSVDB-108594
- Vendor Advisory
GEM
PATCHED VERSIONS
None.
DESCRIPTION
gnms Gem for Ruby contains a flaw in /lib/cmd_parse.rb that is triggered when handling shell metacharacters passed via the 'ip' variable. This may allow a remote attacker to inject arbitrary commands.