← Back

CVE-2013-2090

nvd nist
Published: May 27, 2014Modified: May 6, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

The set_meta_data function in lib/cremefraiche.rb in the Creme Fraiche gem before 0.6.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in the file name of an email attachment. NOTE: some of these details are obtained from third party information.

Affected (11)

1 product
Creme Fraiche
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Uplawski
Up to 0.6
Version 0.4.5.1
Version 0.4.5.2
Version 0.4.5.4
Version 0.4.5.5
Version 0.4.5.6
Version 0.4.5
Version 0.5.1
Version 0.5.2
Version 0.5.3
Version 0.5

References (10)

Source: secalert@redhat.com
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.