MEDIUM
lib/ldoce/word.rb in the ldoce 0.0.2 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in (1) an mp3 URL or (2) file name
Published Apr 3, 2013
6.8
MEDIUMCVSS 2.0
EPSS 1.96%
Description
lib/ldoce/word.rb in the ldoce 0.0.2 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in (1) an mp3 URL or (2) file name.
Affected products
No data.
AND
- 0.0.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (12)
- http://archives.neohapsis.com/archives/bugtraq/2013-04/0010.html mailing-listx_refsource_BUGTRAQExploit
- http://osvdb.org/91870 vdb-entryx_refsource_OSVDB
- http://otiose.dhs.org/advisories/ldoce-0.0.2-cmd-exec.html x_refsource_MISCExploit
- http://www.openwall.com/lists/oss-security/2013/03/31/3 mailing-listx_refsource_MLISTExploit
- http://www.securityfocus.com/bid/58783 vdb-entryx_refsource_BIDExploit
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-0234 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83163 vdb-entryx_refsource_XF
- https://github.com/advisories/GHSA-g266-3crh-h7gj Advisory
- https://github.com/markburns/ldoce/issues/1
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ldoce/CVE-2013-1911.yml
- https://nvd.nist.gov/vuln/detail/CVE-2013-1911
- https://web.archive.org/web/20200229102422/http://www.securityfocus.com/bid/58783
| Link | Providers | Tags |
|---|---|---|
| http://archives.neohapsis.com/archives/bugtraq/2013-04/0010.html | mailing-listx_refsource_BUGTRAQExploit | |
| http://osvdb.org/91870 | vdb-entryx_refsource_OSVDB | |
| http://otiose.dhs.org/advisories/ldoce-0.0.2-cmd-exec.html | x_refsource_MISCExploit | |
| http://www.openwall.com/lists/oss-security/2013/03/31/3 | mailing-listx_refsource_MLISTExploit | |
| http://www.securityfocus.com/bid/58783 | vdb-entryx_refsource_BIDExploit | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-0234 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/83163 | vdb-entryx_refsource_XF | |
| https://github.com/advisories/GHSA-g266-3crh-h7gj | Advisory | |
| https://github.com/markburns/ldoce/issues/1 | ||
| https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ldoce/CVE-2013-1911.yml | ||
| https://nvd.nist.gov/vuln/detail/CVE-2013-1911 | ||
| https://web.archive.org/web/20200229102422/http://www.securityfocus.com/bid/58783 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 3, 2013
Updated Aug 6, 2024
Reserved Feb 19, 2013
Link CVE-2013-1911
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2017-0234 GHSA-G266-3CRH-H7GJ Assigner redhat
Published Apr 3, 2013
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2017-0234