← Back

CVE-2013-4136

nvd nist
Published: Sep 30, 2013Modified: Apr 29, 2026

JSON object

Loading...
4.4
Vector
AV:L/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 3.4 / Impact: 6.4
Source: NVD

Description

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

Affected (5)

Products: Phusion: Passenger
1 product
Passenger
Configuration A
5 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Phusion
Up to 4.0.5
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Running on/withPlatform Versions
Ruby Lang
Ruby
All versions

Timeline

No history available yet.