CVE-2013-4136

EPSS 0.04%

insecure temporary directory usage in passenger

Published: 10/24/2017Modified: 4/28/2026

Description

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

Affected packages (2)

References (10)