converter.rb in the md2pdf gem 0.0.1 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Md2pdf |
Rob_westgeest |
0.0.1 (including) |
0.0.1 (including) |
References