4.6
CVSSv2

CVE-2013-2119

Published: 03/01/2014 Updated: 13/02/2023
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Phusion Passenger gem prior to 3.0.21 and 4.0.x prior to 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phusion passenger

phusion passenger 3.0.0

phusion passenger 3.0.1

phusion passenger 3.0.2

phusion passenger 3.0.3

phusion passenger 3.0.4

phusion passenger 3.0.5

phusion passenger 3.0.6

phusion passenger 3.0.7

phusion passenger 3.0.8

phusion passenger 3.0.9

phusion passenger 3.0.10

phusion passenger 3.0.11

phusion passenger 3.0.12

phusion passenger 3.0.13

phusion passenger 3.0.14

phusion passenger 3.0.15

phusion passenger 3.0.17

phusion passenger 3.0.18

phusion passenger 3.0.19

phusion passenger 4.0.1

phusion passenger 4.0.2

phusion passenger 4.0.3

phusion passenger 4.0.4

redhat openshift 1.0

Vendor Advisories

Debian Bug report logs - #717176 ruby-passenger: CVE-2013-4136: insecure tmp files usage Package: ruby-passenger; Maintainer for ruby-passenger is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Source for ruby-passenger is src:passenger (PTS, buildd, popcon) Reported by: Henri Salo < ...
Debian Bug report logs - #710351 ruby-passenger: CVE-2013-2119 Package: ruby-passenger; Maintainer for ruby-passenger is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Source for ruby-passenger is src:passenger (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> ...
Phusion Passenger gem before 3021 and 40x before 405 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem ...