Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-4136

Опубликовано: 30 сент. 2013
Источник: debian

Описание

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
passengerfixed3.0.13debian-1.2package
ruby-passengerfixed3.0.13debian-1.2package
passengerno-dsasqueezepackage
ruby-passengerfixed3.0.13debian-1+deb7u1wheezypackage

Связанные уязвимости

ubuntu
больше 12 лет назад

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

redhat
больше 12 лет назад

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

nvd
больше 12 лет назад

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

github
больше 8 лет назад

insecure temporary directory usage in passenger