PT-2014-2554 · Phusion · Phusion Passenger

Published

2013-07-09

·

Updated

2023-02-13

·

CVE-2013-2119

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Phusion Passenger gem versions 3.0.0 through 3.0.20 Phusion Passenger gem versions 4.0.0 through 4.0.4
Description The issue allows local users to cause a denial of service or gain privileges by pre-creating a temporary config file in a directory with a predictable name in /tmp/ before it is used by the gem.
Recommendations For Phusion Passenger gem versions 3.0.0 through 3.0.20, update to version 3.0.21 or later. For Phusion Passenger gem versions 4.0.0 through 4.0.4, update to version 4.0.5 or later.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2013-2119
GHSA-9QJ7-JVG4-QR2X
MGASA-2013-0205
RHSA-2013:1136
SUSE-SU-2016:0042-1

Affected Products

Phusion Passenger