MEDIUM
GHSA-5f2p-6vjv-2q2m
Sup Code Injection vulnerability
Quick fix
GHSA-5f2p-6vjv-2q2m — sup: upgrade to the fixed version with the command below.
bundle update supDetails
Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an email attachment.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2013-4478[ADVISORY]
- https://github.com/sup-heliotrope/sup/commit/8b46cdbfc14e07ca07d403aa28b0e7bc1c544785[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/sup/CVE-2013-4478.yml[WEB]
- https://github.com/sup-heliotrope/sup[PACKAGE]
- https://web.archive.org/web/20140524005344/http://rubyforge.org/pipermail/sup-talk/2013-October/004996.html[WEB]
- https://web.archive.org/web/20140524012714/http://rubyforge.org/pipermail/sup-talk/2013-August/004993.html[WEB]
- http://rubyforge.org/pipermail/sup-talk/2013-August/004993.html[WEB]
- http://rubyforge.org/pipermail/sup-talk/2013-October/004996.html[WEB]
- http://www.debian.org/security/2012/dsa-2805[WEB]
- http://www.openwall.com/lists/oss-security/2013/10/30/2[WEB]
- http://www.phenoelit.org/stuff/whatsup.txt[WEB]