First published: Wed Mar 20 2013(Updated: )
`lib/mini_magick.rb` in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
rubygems/mini_magick | <3.6.0 | 3.6.0 |
rubygems mini magick | =1.3.1 | |
MiniMagick | =1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2616 has a severity rating that indicates a high risk of arbitrary command execution if exploited.
To fix CVE-2013-2616, upgrade the MiniMagick Gem to version 3.6.0 or later.
CVE-2013-2616 affects users of the MiniMagick Gem versions 1.3.1 and below.
The potential impacts of CVE-2013-2616 include unauthorized remote command execution on the server.
CVE-2013-2616 is relatively common among applications that utilize the affected version of the MiniMagick Gem.