CVE-2013-4136

EPSS 0.04%

insecure temporary directory usage in passenger

發布日:2017/10/24修改日:2026/4/28
也稱為:GHSA-w6rc-q387-vpgqDEBIAN-CVE-2013-4136

描述

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

受影響套件(2)

參考連結(10)