First published: Mon Sep 30 2013(Updated: )
ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Phusion Passenger | <=4.0.5 | |
Phusion Passenger | =4.0.1 | |
Phusion Passenger | =4.0.2 | |
Phusion Passenger | =4.0.3 | |
Phusion Passenger | =4.0.4 | |
Ruby-lang Ruby |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.