CVE-2013-2617: Code Injection
Published Mar 20, 2013
·Updated
lib/curl.rb in the Curl Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
Other sources
lib/curl.rb in the Curl Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
Affected Software
2 affected components
rubygems/curl<=0.0.9
Curl Project Curl Ruby
Event History
Mar 20, 2013
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Oct 24, 2017
Advisory Published
06:33 PM
Frequently Asked Questions
1
What is the severity of CVE-2013-2617?
CVE-2013-2617 has been assigned a high severity due to its potential for remote code execution.
2
How do I fix CVE-2013-2617?
To fix CVE-2013-2617, update the Curl Gem to version 0.0.10 or later.
3
Which versions of the Curl Gem are affected by CVE-2013-2617?
CVE-2013-2617 affects versions of the Curl Gem for Ruby up to and including 0.0.9.
4
How can attackers exploit CVE-2013-2617?
Attackers can exploit CVE-2013-2617 by crafting malicious URLs containing shell metacharacters to execute arbitrary commands.
5
Is CVE-2013-2617 a common vulnerability?
CVE-2013-2617 is known as a common vulnerability impacting Ruby applications using the Curl Gem.