CVE-2014-2322
lib/string_utf_support.rb in the Arabic Prawn 0.0.1 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) downloaded_file or (2) url variable.
Ver en NVDSeveridad
N/A
EPSS
Probabilidad de explotación (próx. 30 días): 0.0100 (1.0%)
Percentil: 77.0%
EPSS: 2026-05-06
Afecta
dynamixsolutions:arabic_prawnDescripción técnica
lib/string_utf_support.rb in the Arabic Prawn 0.0.1 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) downloaded_file or (2) url variable.
Publicada: 2/5/2014, 14:55:07
Última modificación: 6/5/2026, 22:30:45
Referencias
- http://www.openwall.com/lists/oss-security/2014/03/10/8
- http://www.openwall.com/lists/oss-security/2014/03/12/6
- http://www.vapid.dhs.org/advisories/arabic-ruby-gem.html
- http://www.openwall.com/lists/oss-security/2014/03/10/8
- http://www.openwall.com/lists/oss-security/2014/03/12/6
- http://www.vapid.dhs.org/advisories/arabic-ruby-gem.html