CVE-2013-2616: Code Injection
lib/minimagick.rb in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
Other sources
lib/minimagick.rb in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2616?
CVE-2013-2616 has a severity rating that indicates a high risk of arbitrary command execution if exploited.
How do I fix CVE-2013-2616?
To fix CVE-2013-2616, upgrade the MiniMagick Gem to version 3.6.0 or later.
Who is affected by CVE-2013-2616?
CVE-2013-2616 affects users of the MiniMagick Gem versions 1.3.1 and below.
What are the potential impacts of CVE-2013-2616?
The potential impacts of CVE-2013-2616 include unauthorized remote command execution on the server.
Is CVE-2013-2616 a common vulnerability?
CVE-2013-2616 is relatively common among applications that utilize the affected version of the MiniMagick Gem.