CVE-2013-4479

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
07/12/2013
Last modified:
11/04/2025

Description

lib/sup/message_chunks.rb in Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the content_type of an email attachment.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:supmua:sup:*:*:*:*:*:*:*:* 0.13.2 (including)
cpe:2.3:a:supmua:sup:0.13.0:*:*:*:*:*:*:*
cpe:2.3:a:supmua:sup:0.13.1:*:*:*:*:*:*:*
cpe:2.3:a:supmua:sup:0.14.0:*:*:*:*:*:*:*
cpe:2.3:a:supmua:sup:0.14.1:*:*:*:*:*:*:*