[ GLSA 202107-17 ] Mechanize: Command injection

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <[email protected]>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202107-17
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: High
    Title: Mechanize: Command injection
     Date: July 08, 2021
     Bugs: #768609
       ID: 202107-17

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

A file named by an attacker being utilized by Mechanize could result in
arbitrary code execution.

Background
==========

Mechanize is a Ruby library used for automating interaction with
websites.

Affected packages
=================

    -------------------------------------------------------------------
     Package              /     Vulnerable     /            Unaffected
    -------------------------------------------------------------------
  1  dev-ruby/mechanize           < 2.7.7                    >= 2.7.7 

Description
===========

Mechanize does not neutralize filename input and could allow arbitrary
code execution if an attacker can control filenames used by Mechanize.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All Mechanize users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=dev-ruby/mechanize-2.7.7"

References
==========

[ 1 ] CVE-2021-21289
      https://nvd.nist.gov/vuln/detail/CVE-2021-21289

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202107-17

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2021 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEElFuPenBj6NvNLoABXP0dAeB+IzgFAmDmc9sACgkQXP0dAeB+
IzhK7BAAjfSHooFSv20mctjtxT8UKZVFyeFxFXWEg5t6kmsu99qlKZdLayT4eA7I
IancOmSgC2FCjzp29Wn2AcNgbkVq/G9B7fGf+a0xjx2J9sNO5KeBBVz36PqQYH6B
PK7v4c/fdzMffG6y93lMII5VO20JhxRscyFwkSqOQ2rU2ff5vwtgRCJYUSEwA5IX
8qp38FYZB6ZjGkMPZoYVfY5V7c5Zy0rEIDYRWStF11SEvVo5pqcwFxWvVQL+eoiF
QmlLei0PLXwGza9AHMhvZYxpF6xMK8hVc+vFQepISAxQNKzfUxHS/T2jQlSSxc9M
iIlhl8t91luRz4F3z9tuQHARksM2Xs8Ff4QcjgU8+BOTk+QN2+YK9x7g9m3M+D9k
eooDXqQm+79LGZdE3gngKqkvcAjLtJPDoosDvlMYNfpGuh0mbYsh7GIBPekjREFy
c93eAFY0dCXvblKcbxqfMIudrrz/aKYrfjZB9KQfKvHOF4EMwW/eVRz9Nj8KtzdI
wOXEHeLTtsnvClCm1/+Pg7x6g7KJm0cW8Ezmkl9fA/Z9Es8kQsmWRKdmCf7ryfi3
3xjzMFf8FUqaDt1M8GkjJaCJQToFprV56fXSBSNAQx0/ohTmhysWbjOLzsUxACO+
wtx/kC8y0Eti69r5GzvNEDxbsno/kqy+PDXBndwSvnb1AzZJb7U=
=4Fst
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.