102204vdb entry
http://www.securityfocus.com/bid/102204 CVE-2017-17405
HIGH
Ruby < 2.2.8 / < 2.3.5 / < 2.4.2 / < 2.5.0-preview1 - 'NET::Ftp' Command Injection
Record summary
CVE-2017-17405 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the localfile argument starts with the "|" pipe character, the command following the pipe character is executed. The default value of localfile is File.basename(remotefile), so malicious FTP servers could cause arbitrary command execution.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBRuby < 2.2.8 / < 2.3.5 / < 2.4.2 / < 2.5.0-preview1 - 'NET::Ftp' Command InjectionExploitDB exploitby Etienne StalmansNot analyzed1 file
References
Showing 12 of 151042004vdb entry
http://www.securitytracker.com/id/1042004 RHSA-2018:0378Vendor advisory
https://access.redhat.com/errata/RHSA-2018:0378 RHSA-2018:0583Vendor advisory
https://access.redhat.com/errata/RHSA-2018:0583 RHSA-2018:0584Vendor advisory
https://access.redhat.com/errata/RHSA-2018:0584 RHSA-2018:0585Vendor advisory
https://access.redhat.com/errata/RHSA-2018:0585 RHSA-2019:2806Vendor advisory
https://access.redhat.com/errata/RHSA-2019:2806 [debian-lts-announce] 20171225 [SECURITY] [DLA 1222-1] ruby1.8 security updatemailing list
https://lists.debian.org/debian-lts-announce/2017/12/msg00024.html [debian-lts-announce] 20171225 [SECURITY] [DLA 1221-1] ruby1.9.1 security updatemailing list
https://lists.debian.org/debian-lts-announce/2017/12/msg00025.html [debian-lts-announce] 20180714 [SECURITY] [DLA 1421-1] ruby2.1 security updatemailing list
https://lists.debian.org/debian-lts-announce/2018/07/msg00012.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-17405 DSA-4259Vendor advisory
https://www.debian.org/security/2018/dsa-4259