Vulnerability Description
lib/dragonfly/imagemagickutils.rb in the fog-dragonfly gem 0.8.2 for Ruby allows remote attackers to execute arbitrary commands via unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mark Evans | Fog-Dragonfly | 0.8.2 |
References
- http://seclists.org/fulldisclosure/2013/Sep/18Exploit
- http://seclists.org/oss-sec/2013/q3/526Exploit
- http://seclists.org/oss-sec/2013/q3/528Exploit
- http://www.osvdb.org/96798
- http://www.vapid.dhs.org/advisories/fog-dragonfly-0.8.2-cmd-inj.htmlExploit
- http://seclists.org/fulldisclosure/2013/Sep/18Exploit
- http://seclists.org/oss-sec/2013/q3/526Exploit
- http://seclists.org/oss-sec/2013/q3/528Exploit
- http://www.osvdb.org/96798
- http://www.vapid.dhs.org/advisories/fog-dragonfly-0.8.2-cmd-inj.htmlExploit
FAQ
What is CVE-2013-5671?
CVE-2013-5671 is a vulnerability with a CVSS score of 7.5 (HIGH). lib/dragonfly/imagemagickutils.rb in the fog-dragonfly gem 0.8.2 for Ruby allows remote attackers to execute arbitrary commands via unspecified vectors.
How severe is CVE-2013-5671?
CVE-2013-5671 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-5671?
Check the references section above for vendor advisories and patch information. Affected products include: Mark Evans Fog-Dragonfly.