CVE-2015-7541

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
08/01/2016
Last modified:
12/04/2025

Description

The initialize method in the Histogram class in lib/colorscore/histogram.rb in the colorscore gem before 0.0.5 for Ruby allows context-dependent attackers to execute arbitrary code via shell metacharacters in the (1) image_path, (2) colors, or (3) depth variable.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:colorscore_project:colorscore:*:*:*:*:*:ruby:*:* 0.0.4 (including)