CVE-2013-4136
30.09.2013, 21:55
ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.
Vendor | Product | Version |
---|---|---|
phusion | passenger | 𝑥 ≤ 4.0.5 |
phusion | passenger | 4.0.1 |
phusion | passenger | 4.0.2 |
phusion | passenger | 4.0.3 |
phusion | passenger | 4.0.4 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
passenger |
| ||||||||||||||||||||||||
ruby-passenger |
|
References