CVE Vulnerabilities

CVE-2013-2119

Published: Jan 03, 2014 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
4.6 MODERATE
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary config file in a directory with a predictable name in /tmp/ before it is used by the gem.

Affected Software

NameVendorStart VersionEnd Version
PassengerPhusion*3.0.20 (including)
PassengerPhusion3.0.0 (including)3.0.0 (including)
PassengerPhusion3.0.1 (including)3.0.1 (including)
PassengerPhusion3.0.2 (including)3.0.2 (including)
PassengerPhusion3.0.3 (including)3.0.3 (including)
PassengerPhusion3.0.4 (including)3.0.4 (including)
PassengerPhusion3.0.5 (including)3.0.5 (including)
PassengerPhusion3.0.6 (including)3.0.6 (including)
PassengerPhusion3.0.7 (including)3.0.7 (including)
PassengerPhusion3.0.8 (including)3.0.8 (including)
PassengerPhusion3.0.9 (including)3.0.9 (including)
PassengerPhusion3.0.10 (including)3.0.10 (including)
PassengerPhusion3.0.11 (including)3.0.11 (including)
PassengerPhusion3.0.12 (including)3.0.12 (including)
PassengerPhusion3.0.13 (including)3.0.13 (including)
PassengerPhusion3.0.14 (including)3.0.14 (including)
PassengerPhusion3.0.15 (including)3.0.15 (including)
PassengerPhusion3.0.17 (including)3.0.17 (including)
PassengerPhusion3.0.18 (including)3.0.18 (including)
PassengerPhusion3.0.19 (including)3.0.19 (including)
PassengerPhusion4.0.1 (including)4.0.1 (including)
PassengerPhusion4.0.2 (including)4.0.2 (including)
PassengerPhusion4.0.3 (including)4.0.3 (including)
PassengerPhusion4.0.4 (including)4.0.4 (including)
RHEL 6 Version of OpenShift Enterprise 1.2RedHatruby193-rubygem-passenger-0:3.0.21-3.el6op*
RHEL 6 Version of OpenShift Enterprise 1.2RedHatrubygem-file-tail-0:1.0.5-4.el6op*
RHEL 6 Version of OpenShift Enterprise 1.2RedHatrubygem-passenger-0:3.0.21-3.el6op*
RHEL 6 Version of OpenShift Enterprise 1.2RedHatrubygem-spruz-0:0.2.5-4.el6op*
Ruby-passengerUbuntuquantal*
Ruby-passengerUbunturaring*
Ruby-passengerUbuntuupstream*

References