CVE-2013-2119
published 2014-01-03CVE-2013-2119: Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain…
PriorityP415medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.40%
32.7th percentile
Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phusion | passenger | <= 3.0.20 | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | >= 0 < 3.0.21 | 3.0.21 |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Phusion Passenger Denial of Service
osv·2017-10-24
CVE-2013-2119 [MEDIUM] Phusion Passenger Denial of Service
Phusion Passenger Denial of Service
Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in `/tmp/` before it is used by the gem.
GHSA
Phusion Passenger Denial of Service
ghsa·2017-10-24
CVE-2013-2119 [MEDIUM] CWE-377 Phusion Passenger Denial of Service
Phusion Passenger Denial of Service
Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in `/tmp/` before it is used by the gem.
OSV
CVE-2013-2119: Phusion Passenger gem before 3
osv·2014-01-03·CVSS 4.6
CVE-2013-2119 [MEDIUM] CVE-2013-2119: Phusion Passenger gem before 3
Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.
Red Hat
rubygem-passenger: incorrect temporary file usage
vendor_redhat·2013-05-29·CVSS 4.6
CVE-2013-2119 [MEDIUM] CWE-377 rubygem-passenger: incorrect temporary file usage
rubygem-passenger: incorrect temporary file usage
Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4136 rubygem-passenger: insecure temporary directory usage due to reuse of existing server instance directories
bugzilla·2013-07-18·CVSS 4.6
CVE-2013-4136 [MEDIUM] CVE-2013-4136 rubygem-passenger: insecure temporary directory usage due to reuse of existing server instance directories
CVE-2013-4136 rubygem-passenger: insecure temporary directory usage due to reuse of existing server instance directories
It was reported [1],[2] that Phusion Passenger would reuse existing server instance directories (temporary directories) which could cause Passenger to remove or overwrite files belonging to other instances. This has been corrected in upstream version 4.0.8 [3] via two fixes (the initial fix [4] and a regression fix [5]; both are required to fully fix the issue). This is an issue similar to CVE-2013-2119.
[1] http://www.openwall.com/lists/oss-security/2013/07/15/2
[2] https://code.google.com/p/phusion-passenger/issues/detail?id=910
[3] http://blog.phusion.nl/2013/07/09/phusion-passenger-4-0-8-released/
[4] https://github.com/phusion/passenger/commit/5483b3292cc2af1c8303
Bugzilla
CVE-2013-2119 rubygem-passenger: incorrect temporary file usage [fedora-all]
bugzilla·2013-05-30·CVSS 4.6
CVE-2013-2119 [MEDIUM] CVE-2013-2119 rubygem-passenger: incorrect temporary file usage [fedora-all]
CVE-2013-2119 rubygem-passenger: incorrect temporary file usage [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affe
Bugzilla
CVE-2013-2119 rubygem-passenger: incorrect temporary file usage [epel-6]
bugzilla·2013-05-30·CVSS 4.6
CVE-2013-2119 [MEDIUM] CVE-2013-2119 rubygem-passenger: incorrect temporary file usage [epel-6]
CVE-2013-2119 rubygem-passenger: incorrect temporary file usage [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bug for rub
Bugzilla
CVE-2013-2119 rubygem-passenger: incorrect temporary file usage
bugzilla·2013-01-07·CVSS 4.6
CVE-2013-2119 [MEDIUM] CVE-2013-2119 rubygem-passenger: incorrect temporary file usage
CVE-2013-2119 rubygem-passenger: incorrect temporary file usage
Michael Scherer reported that the passenger ruby gem, when used in standalone mode, does not use temporary files in a secure manner. In the lib/phusion_passenger/standalone/main.rb's create_nginx_controller function, passenger creates an nginx configuration file insecurely and starts nginx with that configuration file:
@temp_dir = "/tmp/passenger-standalone.#{$$}"
@config_filename = "#{@temp_dir}/config"
If a local attacker were able to create a temporary directory that passenger uses and supply a custom nginx configuration file they could start an nginx instance with their own configuration file. This could result in a denial of service condition for a legitimate service or, if passenger were executed as root (in order to
http://blog.phusion.nl/2013/05/29/phusion-passenger-3-0-21-released/http://blog.phusion.nl/2013/05/29/phusion-passenger-4-0-5-released/http://rhn.redhat.com/errata/RHSA-2013-1136.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=892813http://blog.phusion.nl/2013/05/29/phusion-passenger-3-0-21-released/http://blog.phusion.nl/2013/05/29/phusion-passenger-4-0-5-released/http://rhn.redhat.com/errata/RHSA-2013-1136.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=892813
2014-01-03
Published