Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-4136

Опубликовано: 30 сент. 2013
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.4

Описание

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

РелизСтатусПримечание
devel

not-affected

esm-apps/xenial

not-affected

esm-infra-legacy/trusty

DNE

lucid

ignored

end of life
precise

ignored

end of life
precise/esm

DNE

precise was needed
quantal

DNE

raring

DNE

saucy

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [4.0.37-2]]
lucid

DNE

precise

DNE

precise/esm

DNE

quantal

ignored

end of life
raring

ignored

end of life
saucy

ignored

end of life
trusty

not-affected

4.0.37-2
trusty/esm

DNE

trusty was not-affected [4.0.37-2]

Показывать по

EPSS

Процентиль: 13%
0.00044
Низкий

4.4 Medium

CVSS2

Связанные уязвимости

redhat
больше 12 лет назад

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

nvd
больше 12 лет назад

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

debian
больше 12 лет назад

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 f ...

github
больше 8 лет назад

insecure temporary directory usage in passenger

EPSS

Процентиль: 13%
0.00044
Низкий

4.4 Medium

CVSS2