Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9qj7-jvg4-qr2x

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

Phusion Passenger Denial of Service

Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.

Пакеты

Наименование

passenger

rubygems
Затронутые версииВерсия исправления

< 3.0.21

3.0.21

Наименование

passenger

rubygems
Затронутые версииВерсия исправления

>= 4.0.1, < 4.0.5

4.0.5

EPSS

Процентиль: 17%
0.00056
Низкий

Дефекты

CWE-377

Связанные уязвимости

ubuntu
около 12 лет назад

Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.

redhat
больше 12 лет назад

Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.

nvd
около 12 лет назад

Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.

debian
около 12 лет назад

Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby al ...

EPSS

Процентиль: 17%
0.00056
Низкий

Дефекты

CWE-377