CVE-2012-6135: Input Validation
Published Nov 19, 2019
·Updated
RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
Affected Software
4 affected components
debian/ruby-passenger
Phusion Passenger Ruby=4.0.0-beta1
Phusion Passenger Ruby=4.0.0-beta2
redhat Openshift=1.0
Remediation
Patch Available
Patch Available
Event History
Nov 19, 2019
CVE Published
via MITRE·04:56 PM
Data Sourced
via MITRE·04:56 PM
DescriptionWeakness
Aug 6, 2024
Data Sourced
via Debian·09:34 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2012-6135?
The severity of CVE-2012-6135 is high with a CVSS score of 7.5.
2
What is the affected software for CVE-2012-6135?
The affected software for CVE-2012-6135 includes RubyGems passenger 4.0.0 betas 1 and 2, as well as IBM Robotic Process Automation as a Service.
3
How can remote attackers exploit CVE-2012-6135?
Remote attackers can exploit CVE-2012-6135 to delete arbitrary files during the startup process.
4
Is there a fix available for CVE-2012-6135?
There is no specific fix available for CVE-2012-6135, but it is recommended to update to a newer version of RubyGems passenger or apply any available patches.