Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=892813 | issue tracking third party advisory |
http://rhn.redhat.com/errata/RHSA-2013-1136.html | third party advisory vendor advisory |
http://blog.phusion.nl/2013/05/29/phusion-passenger-3-0-21-released/ | patch vendor advisory |
http://blog.phusion.nl/2013/05/29/phusion-passenger-4-0-5-released/ | patch vendor advisory |