CVE-2013-4136
30.09.2013, 21:55
ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.
| Vendor | Product | Version |
|---|---|---|
| phusion | passenger | 𝑥 ≤ 4.0.5 |
| phusion | passenger | 4.0.1 |
| phusion | passenger | 4.0.2 |
| phusion | passenger | 4.0.3 |
| phusion | passenger | 4.0.4 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| passenger |
| ||||||||||||||||||||||||
| ruby-passenger |
|
References