Phusion Passenger Denial of Service
Moderate severity
GitHub Reviewed
Published
Oct 24, 2017
to the GitHub Advisory Database
•
Updated Jul 5, 2023
Package
Affected versions
< 3.0.21
>= 4.0.1, < 4.0.5
Patched versions
3.0.21
4.0.5
Description
Published by the National Vulnerability Database
Jan 3, 2014
Published to the GitHub Advisory Database
Oct 24, 2017
Reviewed
Jun 16, 2020
Last updated
Jul 5, 2023
Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in
/tmp/
before it is used by the gem.References