Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-4136

Опубликовано: 30 сент. 2013
Источник: debian
EPSS Низкий

Описание

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
passengerfixed3.0.13debian-1.2package
ruby-passengerfixed3.0.13debian-1.2package
passengerno-dsasqueezepackage
ruby-passengerfixed3.0.13debian-1+deb7u1wheezypackage

EPSS

Процентиль: 25%
0.00329
Низкий

Связанные уязвимости

ubuntu
почти 13 лет назад

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

redhat
около 13 лет назад

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

nvd
почти 13 лет назад

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

github
почти 9 лет назад

insecure temporary directory usage in passenger

EPSS

Процентиль: 25%
0.00329
Низкий