GHSA-99ch-8mvp-g7m5

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-99ch-8mvp-g7m5/GHSA-99ch-8mvp-g7m5.json
Aliases
  • CVE-2013-1948
Published
2017-10-24T18:33:37Z
Modified
2023-03-18T05:46:24.849638Z
Details

converter.rb in the md2pdf gem 0.0.1 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename.

References

Affected packages

RubyGems / md2pdf

md2pdf

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0

Affected versions

0.*

0.0.1

Database specific

{
    "last_known_affected_version_range": "<= 0.0.1"
}