Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-6325-6g32-7p35: flash_tool Gem for Ruby File Download Handling Arbitrary Command Execution

flash_tool Gem for Ruby contains a flaw that is triggered during the handling of downloaded files that contain shell characters. With a specially crafted file, a context-dependent attacker can execute arbitrary commands.

ghsa
#git#ruby

flash_tool Gem for Ruby File Download Handling Arbitrary Command Execution

High severity GitHub Reviewed Published Jan 26, 2023 to the GitHub Advisory Database • Updated Jan 26, 2023

Related news

CVE-2013-2513: CVE-2013-2513 - GitHub Advisory Database

The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file.