Multiple Ruby dragonfly Gem Remote Command Execution Vulnerabilities
Release date:
Updated on:
Affected Systems:
Dragonfly 1.0.5
Description:
--------------------------------------------------------------------------------
Bugtraq id: 69395
Dragonfly is an Rack framework for dynamic image processing.
Dragonfly 1.0.5 and other versions have multiple Remote Command Execution Vulnerabilities. Attackers can exploit these vulnerabilities to execute arbitrary commands in the context of the affected application.
<* Source: leex
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Dragonfly
---------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Https://github.com/markevans/dragonfly
This article permanently updates the link address: