CVE-2013-4478
medium
CVSS v3
—
CVSS v2
6.8
VIR risk
6.8
Description
Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an email attachment.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-4478
Vendor advisory: secalert@redhat.com — https://github.com/sup-heliotrope/sup/commit/8b46cdbfc14e07ca07d403aa28b0e7bc1c544785
Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/55400
Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/55294
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 0.12.1+git20120407.aaa852f-1+deb7u1 |
| debian | bullseye | fixed | 0.12.1+git20120407.aaa852f-1+deb7u1 |
| debian | forky | fixed | 0.12.1+git20120407.aaa852f-1+deb7u1 |
| debian | sid | fixed | 0.12.1+git20120407.aaa852f-1+deb7u1 |
| debian | trixie | fixed | 0.12.1+git20120407.aaa852f-1+deb7u1 |
References
- https://web.archive.org/web/20140524012714/http://rubyforge.org/pipermail/sup-talk/2013-August/004993.html
- http://rubyforge.org/pipermail/sup-talk/2013-August/004993.html
- http://rubyforge.org/pipermail/sup-talk/2013-October/004996.html
- http://secunia.com/advisories/55294
- http://secunia.com/advisories/55400
- http://www.debian.org/security/2012/dsa-2805
- http://www.openwall.com/lists/oss-security/2013/10/30/2
- https://github.com/sup-heliotrope/sup/commit/8b46cdbfc14e07ca07d403aa28b0e7bc1c544785
- https://nvd.nist.gov/vuln/detail/CVE-2013-4478
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/sup/CVE-2013-4478.yml
- https://github.com/sup-heliotrope/sup
- https://web.archive.org/web/20140524005344/http://rubyforge.org/pipermail/sup-talk/2013-October/004996.html
- http://www.phenoelit.org/stuff/whatsup.txt
- https://security-tracker.debian.org/tracker/CVE-2013-4478
CWEs
CWE-94
Verify integrity in audit chain (admin only). AS-IS.