Описание
Phusion Passenger before 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenStack Platform 4 | ruby193-rubygem-passenger | Will not fix | ||
| Red Hat OpenStack Platform 4 | rubygem-passenger | Will not fix | ||
| Red Hat Software Collections | ruby193-rubygem-passenger40 | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Low
Дефект:
CWE-377
https://bugzilla.redhat.com/show_bug.cgi?id=1058992rubygem-passenger: insecure use of temporary files
2.1 Low
CVSS2
Связанные уязвимости
ubuntu
почти 11 лет назад
Phusion Passenger before 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file.
nvd
почти 11 лет назад
Phusion Passenger before 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file.
debian
почти 11 лет назад
Phusion Passenger before 4.0.37 allows local users to write to certain ...
2.1 Low
CVSS2