{"id":"GHSA-w248-xr37-jx8m","summary":"fastreader Gem for Ruby URI Handling Arbitrary Command Injection","details":"fastreader Gem for Ruby contains a flaw that is triggered during the handling of specially crafted input passed via a URL that contains a ';' character. This may allow a context-dependent attacker to potentially execute arbitrary commands.","aliases":["CVE-2013-2615"],"modified":"2024-12-03T06:14:23.814364Z","published":"2017-10-24T18:33:37Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:59:12Z","nvd_published_at":null,"cwe_ids":["CWE-94"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-2615"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/fastreader/CVE-2013-2615.yml"},{"type":"WEB","url":"http://packetstormsecurity.com/files/120776/Ruby-Gem-Fastreader-1.0.8-Command-Execution.html"},{"type":"WEB","url":"http://packetstormsecurity.com/files/120845/Ruby-Gem-Fastreader-1.0.8-Code-Execution.html"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2013/Mar/122"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2013/03/19/9"}],"affected":[{"package":{"name":"fastreader","ecosystem":"RubyGems","purl":"pkg:gem/fastreader"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-w248-xr37-jx8m/GHSA-w248-xr37-jx8m.json"}}],"schema_version":"1.9.0"}