Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-10345

Опубликовано: 09 нояб. 2016
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the passenger user.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.3ruby193-rubygem-passengerNot affected
Red Hat Ceph Storage 1.3rubygem-passengerNot affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installerruby193-rubygem-passengerWill not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installerrubygem-passengerWill not fix
Red Hat OpenShift Enterprise 2ruby-193-rubygem-passengerWill not fix
Red Hat OpenShift Enterprise 2ruby200-rubygem-passengerWill not fix
Red Hat OpenShift Enterprise 2rubygem-passengerWill not fix
Red Hat Satellite 6ruby193-rubygem-passengerNot affected
Red Hat Satellite 6rubygem-passengerNot affected
Red Hat Software Collectionsrh-passenger40-passengerNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1445306passenger: File overwrite vulnerability in passenger-install-nginx-module

EPSS

Процентиль: 20%
0.00064
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 9 лет назад

In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the passenger user.

CVSS3: 7.8
nvd
почти 9 лет назад

In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the passenger user.

CVSS3: 7.8
debian
почти 9 лет назад

In Phusion Passenger before 5.1.0, a known /tmp filename was used duri ...

CVSS3: 7.8
github
больше 7 лет назад

Phusion Passenger uses a known /tmp filename

EPSS

Процентиль: 20%
0.00064
Низкий

5.5 Medium

CVSS3