VYPR

RubyGems package

arr-pm

pkg:gem/arr-pm

Vulnerabilities (1)

  • CVE-2022-39224Sep 21, 2022
    affected < 0.0.12fixed 0.0.12

    Arr-pm is an RPM reader/writer library written in Ruby. Versions prior to 0.0.12 are subject to OS command injection resulting in shell execution if the RPM contains a malicious "payload compressor" field. This vulnerability impacts the `extract` and `files` methods of the `RPM::