CVE-2013-4478

medium
Published 2013-10-29 · Modified 2024-12-06
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an email attachment.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-4478

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/sup-heliotrope/sup/commit/8b46cdbfc14e07ca07d403aa28b0e7bc1c544785

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/55400

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/55294

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0.12.1+git20120407.aaa852f-1+deb7u1
debian debianbullseyefixed0.12.1+git20120407.aaa852f-1+deb7u1
debian debianforkyfixed0.12.1+git20120407.aaa852f-1+deb7u1
debian debiansidfixed0.12.1+git20120407.aaa852f-1+deb7u1
debian debiantrixiefixed0.12.1+git20120407.aaa852f-1+deb7u1

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemssup<~> 0.13.2.1~> 0.13.2.1
ruby RubyGemssup<0.13.2.10.13.2.1
ruby RubyGemssup>=0.14.0,<0.14.1.10.14.1.1

Application impact

VendorProductVersionsFixed
supmuasup{"endIncluding":"0.13.2"}
supmuasup0.13.0
supmuasup0.13.1
supmuasup0.14.0
supmuasup0.14.1

References

CWEs

CWE-94

Verify integrity in audit chain (admin only). AS-IS.