Arbitrary Command Injection Affecting quick_magick package, versions >= 0


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Arbitrary Command Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-RUBY-QUICKMAGICK-20012
  • published11 Jan 2011
  • disclosed11 Jan 2011
  • creditUnknown

Introduced: 11 Jan 2011

CVE NOT AVAILABLE CWE-77  (opens in a new tab)

Overview

quick_magick allows you to access ImageMagick command line functions using Ruby interface. Affected versions of this gem contain a flaw in the QuickMagick::Image.read function. The issue is triggered when handling a specially crafted string. This may allow a remote attacker to inject arbitrary commands.

CVSS Scores

version 3.1