Описание
Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 4.0.37-2 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected [4.0.37-2]] |
| lucid | DNE | |
| precise | DNE | |
| quantal | ignored | end of life |
| raring | ignored | end of life |
| saucy | not-affected | 3.0.13debian-1.2 |
| trusty | not-affected | 4.0.37-2 |
| trusty/esm | DNE | trusty was not-affected [4.0.37-2] |
| upstream | released | 3.0.13debian-1.1 |
Показывать по
Ссылки на источники
EPSS
4.6 Medium
CVSS2
Связанные уязвимости
Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.
Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.
Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby al ...
EPSS
4.6 Medium
CVSS2