← Back

CVE-2013-2119

nvd nist
Published: Jan 3, 2014Modified: Apr 29, 2026

JSON object

Loading...
4.6
Vector
AV:L/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 3.9 / Impact: 6.4
Source: NVD

Description

Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.

Affected (25)

1 product
Passenger
1 product
Openshift
Configuration A
24 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Phusion
Up to 3.0.20
Version 3.0.0
Version 3.0.10
Version 3.0.11
Version 3.0.12
Version 3.0.13
Version 3.0.14
Version 3.0.15
Version 3.0.17
Version 3.0.18
Version 3.0.19
Version 3.0.1
Version 3.0.2
Version 3.0.3
Version 3.0.4
Version 3.0.5
Version 3.0.6
Version 3.0.7
Version 3.0.8
Version 3.0.9
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Running on/withPlatform Versions
Ruby Lang
Ruby
All versions
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.0

Related CWEs

References (8)

Source: secalert@redhat.com
PatchVendor Advisory
Source: secalert@redhat.com
PatchVendor Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory

Timeline

No history available yet.