--- gem: sprout cve: 2013-6421 osvdb: 100598 url: http://www.osvdb.org/show/osvdb/100598 title: Sprout Gem for Ruby contains a flaw date: 2013-12-02 description: sprout Gem for Ruby contains a flaw in the unpack_zip() function in archive_unpacker.rb. The issue is due to the program failing to properly sanitize input passed via the 'zip_file', 'dir', 'zip_name', and 'output' parameters. This may allow a context-dependent attacker to execute arbitrary code. cvss_v2: 7.5 patched_versions: unaffected_versions: - '< 0.7.246'