Ruby PDFKit CVE-2013-1607 Parameter Parsing Vulnerability
BID:58303
CVE-2013-1607 |Info
Ruby PDFKit CVE-2013-1607 Parameter Parsing Vulnerability
| Bugtraq ID: | 58303 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-1607 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2013 12:00AM |
| Updated: | Feb 21 2013 12:00AM |
| Credit: | Hans-Martin Münch, it.sec |
| Vulnerable: |
Jared Pace PDFKit 0.5.2 |
| Not Vulnerable: |
Jared Pace PDFKit 0.5.3 |
Exploit / POC
Ruby PDFKit CVE-2013-1607 Parameter Parsing Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Ruby PDFKit CVE-2013-1607 Parameter Parsing Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Ruby PDFKit CVE-2013-1607 Parameter Parsing Vulnerability
References:
References:
- PDFKit 0.5.3 Changelog (Jared Pace)
- PDFKit Homepage (Jared Pace)
- Unsanitized String Vulnerability in PDFKit <= 0.5.2 (Jared Pace)