Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w6rc-q387-vpgq

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

insecure temporary directory usage in passenger

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

Пакеты

Наименование

passenger

rubygems
Затронутые версииВерсия исправления

< 4.0.6

4.0.6

EPSS

Процентиль: 13%
0.00044
Низкий

Дефекты

CWE-59

Связанные уязвимости

ubuntu
больше 12 лет назад

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

redhat
больше 12 лет назад

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

nvd
больше 12 лет назад

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

debian
больше 12 лет назад

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 f ...

EPSS

Процентиль: 13%
0.00044
Низкий

Дефекты

CWE-59