RubySec

Providing security resources for the Ruby community

OSVDB-108594 (gnms): gnms Gem for Ruby /lib/cmd_parse.rb ip Variable Shell Metacharacter Handling Remote Command Injection

ADVISORIES

GEM

gnms

PATCHED VERSIONS

None.

DESCRIPTION

gnms Gem for Ruby contains a flaw in /lib/cmd_parse.rb that is triggered when handling shell metacharacters passed via the ‘ip’ variable. This may allow a remote attacker to inject arbitrary commands.

RELATED