CVE-2015-7541 Information

Description

The initialize method in the Histogram class in lib/colorscore/histogram.rb in the colorscore gem before 0.0.5 for Ruby allows context-dependent attackers to execute arbitrary code via shell metacharacters in the (1) image_path (2) colors or (3) depth variable.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Reference

http://rubysec.com/advisories/CVE-2015-7541/ http://www.openwall.com/lists/oss-security/2016/01/05/2 https://github.com/quadule/colorscore/commit/570b5e854cecddd44d2047c44126aed951b61718

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

CHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

10.0

Share on: