CVE-2013-4136
published 2013-09-30CVE-2013-4136: ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of…
PriorityP421medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.33%
25.3th percentile
ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | passenger | < passenger 3.0.13debian-1.2 (bookworm) | passenger 3.0.13debian-1.2 (bookworm) |
| phusion | passenger | <= 4.0.5 | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | — | — |
| phusion | passenger | >= 0 < 3.0.13debian-1.2 | 3.0.13debian-1.2 |
| phusion | passenger | >= 0 < 3.0.13debian-1.2 | 3.0.13debian-1.2 |
| phusion | passenger | >= 0 < 3.0.13debian-1.2 | 3.0.13debian-1.2 |
| phusion | passenger | >= 0 < 3.0.13debian-1.2 | 3.0.13debian-1.2 |
| phusion | passenger | >= 0 < 4.0.6 | 4.0.6 |
CVSS provenance
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
insecure temporary directory usage in passenger
osv·2017-10-24
CVE-2013-4136 [MEDIUM] insecure temporary directory usage in passenger
insecure temporary directory usage in passenger
ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.
GHSA
insecure temporary directory usage in passenger
ghsa·2017-10-24
CVE-2013-4136 [MEDIUM] CWE-59 insecure temporary directory usage in passenger
insecure temporary directory usage in passenger
ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.
OSV
CVE-2013-4136: ext/common/ServerInstanceDir
osv·2013-09-30·CVSS 4.4
CVE-2013-4136 [MEDIUM] CVE-2013-4136: ext/common/ServerInstanceDir
ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.
Red Hat
rubygem-passenger: insecure temporary directory usage due to reuse of existing server instance directories
vendor_redhat·2013-06-20·CVSS 4.4
CVE-2013-4136 [MEDIUM] rubygem-passenger: insecure temporary directory usage due to reuse of existing server instance directories
rubygem-passenger: insecure temporary directory usage due to reuse of existing server instance directories
ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.
Debian
CVE-2013-4136: passenger - ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby al...
vendor_debian·2013·CVSS 4.4
CVE-2013-4136 [MEDIUM] CVE-2013-4136: passenger - ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby al...
ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.
Scope: local
bookworm: resolved (fixed in 3.0.13debian-1.2)
bullseye: resolved (fixed in 3.0.13debian-1.2)
forky: resolved (fixed in 3.0.13debian-1.2)
sid: resolved (fixed in 3.0.13debian-1.2)
trixie: resolved (fixed in 3.0.13debian-1.2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4136 rubygem-passenger: insecure temporary directory usage due to reuse of existing server instance directories
bugzilla·2013-07-18·CVSS 4.6
CVE-2013-4136 [MEDIUM] CVE-2013-4136 rubygem-passenger: insecure temporary directory usage due to reuse of existing server instance directories
CVE-2013-4136 rubygem-passenger: insecure temporary directory usage due to reuse of existing server instance directories
It was reported [1],[2] that Phusion Passenger would reuse existing server instance directories (temporary directories) which could cause Passenger to remove or overwrite files belonging to other instances. This has been corrected in upstream version 4.0.8 [3] via two fixes (the initial fix [4] and a regression fix [5]; both are required to fully fix the issue). This is an issue similar to CVE-2013-2119.
[1] http://www.openwall.com/lists/oss-security/2013/07/15/2
[2] https://code.google.com/p/phusion-passenger/issues/detail?id=910
[3] http://blog.phusion.nl/2013/07/09/phusion-passenger-4-0-8-released/
[4] https://github.com/phusion/passenger/commit/5483b3292cc2af1c8303
Bugzilla
rubygem-passenger: CVE-2013-4136 rubygem-passenger: insecure temporary directory usage due to reuse of existing server instance directories [fedora-all]
bugzilla·2013-07-18·CVSS 4.4
CVE-2013-4136 [MEDIUM] rubygem-passenger: CVE-2013-4136 rubygem-passenger: insecure temporary directory usage due to reuse of existing server instance directories [fedora-all]
rubygem-passenger: CVE-2013-4136 rubygem-passenger: insecure temporary directory usage due to reuse of existing server instance directories [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM chang
http://rhn.redhat.com/errata/RHSA-2013-1136.htmlhttp://www.openwall.com/lists/oss-security/2013/07/16/6https://code.google.com/p/phusion-passenger/issues/detail?id=910https://github.com/phusion/passenger/blob/release-4.0.6/NEWShttps://github.com/phusion/passenger/commit/5483b3292cc2af1c83033eaaadec20dba4dcfd9bhttp://rhn.redhat.com/errata/RHSA-2013-1136.htmlhttp://www.openwall.com/lists/oss-security/2013/07/16/6https://code.google.com/p/phusion-passenger/issues/detail?id=910https://github.com/phusion/passenger/blob/release-4.0.6/NEWShttps://github.com/phusion/passenger/commit/5483b3292cc2af1c83033eaaadec20dba4dcfd9b
2013-09-30
Published