OSVDB-106954: QuickMagick::Image.read Function Crafted String Handling Remote Command Injection
This package contains a flaw in the QuickMagick::Image.read
function. The issue is triggered when handling a specially crafted string. This may allow a remote attacker to inject arbitrary commands.
References
Detect and mitigate OSVDB-106954 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →