GHSA-w248-xr37-jx8m
Dashboard / Vulnerabilities / GHSA-w248-xr37-jx8m
Summary: fastreader Gem for Ruby URI Handling Arbitrary Command Injection
Details: fastreader Gem for Ruby contains a flaw that is triggered during the handling of specially crafted input passed via a URL that contains a ';' character. This may allow a context-dependent attacker to potentially execute arbitrary commands.
References: https://nvd.nist.gov/vuln/detail/CVE-2013-2615, https://github.com/rubysec/ruby-advisory-db/blob/master/gems/fastreader/CVE-2013-2615.yml, http://packetstormsecurity.com/files/120776/Ruby-Gem-Fastreader-1.0.8-Command-Execution.html, http://packetstormsecurity.com/files/120845/Ruby-Gem-Fastreader-1.0.8-Code-Execution.html, http://seclists.org/fulldisclosure/2013/Mar/122, http://www.openwall.com/lists/oss-security/2013/03/19/9
Affected packages
Package
Name: fastreader
Purl: pkg:gem/fastreader
Affected ranges
Type: ECOSYSTEM
Events:
