CVE-2013-2119

Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:phusion:passenger:*:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:3.0.4:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:3.0.5:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:3.0.6:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:3.0.7:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:3.0.8:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:3.0.9:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:3.0.10:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:3.0.11:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:3.0.12:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:3.0.13:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:3.0.14:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:3.0.15:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:3.0.17:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:3.0.18:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:3.0.19:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:phusion:passenger:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:openshift:1.0:*:enterprise:*:*:*:*:*

History

21 Nov 2024, 01:51

Type Values Removed Values Added
References () http://blog.phusion.nl/2013/05/29/phusion-passenger-3-0-21-released/ - Patch, Vendor Advisory () http://blog.phusion.nl/2013/05/29/phusion-passenger-3-0-21-released/ - Patch, Vendor Advisory
References () http://blog.phusion.nl/2013/05/29/phusion-passenger-4-0-5-released/ - Patch, Vendor Advisory () http://blog.phusion.nl/2013/05/29/phusion-passenger-4-0-5-released/ - Patch, Vendor Advisory
References () http://rhn.redhat.com/errata/RHSA-2013-1136.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2013-1136.html - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=892813 - Issue Tracking, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=892813 - Issue Tracking, Third Party Advisory

Information

Published : 2014-01-03 18:54

Updated : 2024-11-21 01:51


NVD link : CVE-2013-2119

Mitre link : CVE-2013-2119

CVE.ORG link : CVE-2013-2119


JSON object : View

Products Affected

phusion

  • passenger

redhat

  • openshift

ruby-lang

  • ruby
CWE
CWE-264

Permissions, Privileges, and Access Controls