First published: Thu Apr 25 2013(Updated: )
`converter.rb` in the md2pdf gem 0.0.1 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
rubygems/md2pdf | <=0.0.1 | |
Rob Westgeest Md2pdf | =0.0.1 | |
Ruby-lang Ruby |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.