{"id":"CVE-2013-5671","aliases":[],"url":"https://o3.security/vulnerability/CVE-2013-5671","summary":"Code injection in dragonfly gem","details":"`lib/dragonfly/imagemagickutils.rb` in the fog-dragonfly gem 0.8.2 for Ruby allows remote attackers to execute arbitrary commands via unspecified vectors.","published":"2017-10-24T18:33:37Z","modified":"2024-12-08T05:34:08.990355Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":4,"affectedPackages":[{"ecosystem":"RubyGems","name":"dragonfly","fixedVersion":"1.0.0"},{"ecosystem":"RubyGems","name":"fog-dragonfly","fixedVersion":null}],"fix":{"url":"https://github.com/github/advisory-database/pull/486","label":"github/advisory-database#486"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-5671"},{"type":"WEB","url":"https://github.com/markevans/dragonfly/issues/520"},{"type":"WEB","url":"https://github.com/github/advisory-database/pull/486"},{"type":"PACKAGE","url":"https://github.com/markevans/dragonfly"},{"type":"WEB","url":"https://web.archive.org/web/20201208033320/http://www.vapid.dhs.org/advisories/fog-dragonfly-0.8.2-cmd-inj.html"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2013/Sep/18"},{"type":"WEB","url":"http://seclists.org/oss-sec/2013/q3/526"},{"type":"WEB","url":"http://seclists.org/oss-sec/2013/q3/528"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-08T05:34:08.990355Z"}}