{"id":"GHSA-99ch-8mvp-g7m5","summary":"md2pdf allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename","details":"`converter.rb` in the md2pdf gem 0.0.1 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename.","aliases":["CVE-2013-1948"],"modified":"2024-11-29T05:41:09.418065Z","published":"2017-10-24T18:33:37Z","database_specific":{"cwe_ids":[],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:28:02Z","nvd_published_at":"2013-04-25T23:55:01Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-1948"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/83416"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/md2pdf/CVE-2013-1948.yml"},{"type":"PACKAGE","url":"https://github.com/rwestgeest/md2pdf"},{"type":"WEB","url":"https://web.archive.org/web/20130503194109/http://www.securityfocus.com/bid/59061"},{"type":"WEB","url":"http://vapid.dhs.org/advisories/md2pdf-remote-exec.html"}],"affected":[{"package":{"name":"md2pdf","ecosystem":"RubyGems","purl":"pkg:gem/md2pdf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.0.1"}]}],"versions":["0.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-99ch-8mvp-g7m5/GHSA-99ch-8mvp-g7m5.json"}}],"schema_version":"1.9.0"}