CVE-2018-12029
published 2018-06-17CVE-2018-12029: A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard…
PriorityP431high7CVSS 3.0
AVLACHPRLUINSUCHIHAH
EPSS
0.28%
19.8th percentile
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but before it was chowned, leads to the target of the link being chowned via the path. Targeting sensitive files such as root's crontab file allows privilege escalation.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | passenger | < passenger 5.0.30-1.1 (bookworm) | passenger 5.0.30-1.1 (bookworm) |
| phusion | passenger | >= 0 < 5.0.30-1.1 | 5.0.30-1.1 |
| phusion | passenger | >= 0 < 5.0.30-1.1 | 5.0.30-1.1 |
| phusion | passenger | >= 0 < 5.0.30-1.1 | 5.0.30-1.1 |
| phusion | passenger | >= 0 < 5.0.30-1.1 | 5.0.30-1.1 |
| phusion | passenger | >= 0 < 5.0.27-2ubuntu0.1~esm1 | 5.0.27-2ubuntu0.1~esm1 |
| phusion | passenger | >= 3.0.0 < 5.3.2 | 5.3.2 |
| phusion | passenger | >= 3.0.0 < 5.3.2 | 5.3.2 |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv7.0HIGH
vendor_debian7.0LOW
vendor_redhat7.0HIGH
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Phusion Passenger vulnerabilities
vendor_ubuntu·2022-02-01·CVSS 4.7
CVE-2017-16355 [MEDIUM] Phusion Passenger vulnerabilities
Title: Phusion Passenger vulnerabilities
Summary: Several security issues were fixed in Phusion Passenger.
It was discovered that Phusion Passenger incorrectly handled a file path in
the application root folder. An attacker could possibly use this issue to
read arbitrary files. (CVE-2017-16355)
It was discovered that Phusion Passenger had a race condition in the nginx
module that could be used to perform a symlink attack. An attacker could
possibly use this issue to escalate privileges. (CVE-2018-12029)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
passenger: CHMOD race condition in nginx_module/ngx_http_passenger_module.c allows for local privilege escalation
vendor_redhat·2018-06-05·CVSS 7.0
CVE-2018-12029 [HIGH] CWE-362 passenger: CHMOD race condition in nginx_module/ngx_http_passenger_module.c allows for local privilege escalation
passenger: CHMOD race condition in nginx_module/ngx_http_passenger_module.c allows for local privilege escalation
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but before it was chowned, leads to the target of the link being chowned via the path. Targeting sensitive files such as root's crontab file allows privilege escalation.
Package: rubygem-passenger (Red Hat Ceph Storage 1.3) - Will not fix
Package: rubygem-passenger (Red Hat Satellite 6) - Not affected
Package: rubygem-passenger (Red Hat Update Infrastructure 3 for Cloud Providers) - Not a
Debian
CVE-2018-12029: passenger - A race condition in the nginx module in Phusion Passenger 3.x through 5.x before...
vendor_debian·2018·CVSS 7.0
CVE-2018-12029 [HIGH] CVE-2018-12029: passenger - A race condition in the nginx module in Phusion Passenger 3.x through 5.x before...
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but before it was chowned, leads to the target of the link being chowned via the path. Targeting sensitive files such as root's crontab file allows privilege escalation.
Scope: local
bookworm: resolved (fixed in 5.0.30-1.1)
bullseye: resolved (fixed in 5.0.30-1.1)
forky: resolved (fixed in 5.0.30-1.1)
sid: resolved (fixed in 5.0.30-1.1)
trixie: resolved (fixed in 5.0.30-1.1)
OSV
Phusion Passenger Race Condition Allows Privilege Escalation
osv·2022-05-14
CVE-2018-12029 [HIGH] Phusion Passenger Race Condition Allows Privilege Escalation
Phusion Passenger Race Condition Allows Privilege Escalation
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but before it was chowned, leads to the target of the link being chowned via the path. Targeting sensitive files such as root's crontab file allows privilege escalation.
GHSA
Phusion Passenger Race Condition Allows Privilege Escalation
ghsa·2022-05-14
CVE-2018-12029 [HIGH] CWE-362 Phusion Passenger Race Condition Allows Privilege Escalation
Phusion Passenger Race Condition Allows Privilege Escalation
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but before it was chowned, leads to the target of the link being chowned via the path. Targeting sensitive files such as root's crontab file allows privilege escalation.
OSV
passenger vulnerabilities
osv·2022-02-01·CVSS 4.7
CVE-2017-16355 [MEDIUM] passenger vulnerabilities
passenger vulnerabilities
It was discovered that Phusion Passenger incorrectly handled a file path in
the application root folder. An attacker could possibly use this issue to
read arbitrary files. (CVE-2017-16355)
It was discovered that Phusion Passenger had a race condition in the nginx
module that could be used to perform a symlink attack. An attacker could
possibly use this issue to escalate privileges. (CVE-2018-12029)
OSV
CVE-2018-12029: A race condition in the nginx module in Phusion Passenger 3
osv·2018-06-17·CVSS 7.0
CVE-2018-12029 [HIGH] CVE-2018-12029: A race condition in the nginx module in Phusion Passenger 3
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but before it was chowned, leads to the target of the link being chowned via the path. Targeting sensitive files such as root's crontab file allows privilege escalation.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-12029 passenger: CHMOD race condition in nginx_module/ngx_http_passenger_module.c allows for local privilege escalation
bugzilla·2018-06-19·CVSS 7.0
CVE-2018-12029 [HIGH] CVE-2018-12029 passenger: CHMOD race condition in nginx_module/ngx_http_passenger_module.c allows for local privilege escalation
CVE-2018-12029 passenger: CHMOD race condition in nginx_module/ngx_http_passenger_module.c allows for local privilege escalation
Phusion Passenger versions 3.0.0 through 5.3.1 are vulnerable to a file system access race condition in the Nginx module that allows for local privilege escalation. The vulnerability was exploitable only when running a non-standard passenger_instance_registry_dir, via a race condition where after a file was created, there was a window in which it could be replaced with a symlink before it was chowned via the path and not the file descriptor.
If the symlink target was to a file which would be executed by root such as root's crontab file, then privilege escalation was possible.
External References:
https://blog.phusion.nl/2018/06/12/passenger-5-3-2-various-sec
Bugzilla
CVE-2018-12029 passenger: CHMOD race condition in nginx_module/ngx_http_passenger_module.c allows for local privilege escalation [epel-7]
bugzilla·2018-06-19·CVSS 7.0
CVE-2018-12029 [HIGH] CVE-2018-12029 passenger: CHMOD race condition in nginx_module/ngx_http_passenger_module.c allows for local privilege escalation [epel-7]
CVE-2018-12029 passenger: CHMOD race condition in nginx_module/ngx_http_passenger_module.c allows for local privilege escalation [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messag
Bugzilla
CVE-2018-12029 passenger: CHMOD race condition in nginx_module/ngx_http_passenger_module.c allows for local privilege escalation [fedora-all]
bugzilla·2018-06-19·CVSS 7.0
CVE-2018-12029 [HIGH] CVE-2018-12029 passenger: CHMOD race condition in nginx_module/ngx_http_passenger_module.c allows for local privilege escalation [fedora-all]
CVE-2018-12029 passenger: CHMOD race condition in nginx_module/ngx_http_passenger_module.c allows for local privilege escalation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commi
Bugzilla
CVE-2017-16652 CVE-2018-11385 CVE-2018-11386 CVE-2018-11406 CVE-2018-11407 CVE-2018-11408 php-symfony: Multiple flaws
bugzilla·2018-06-14·CVSS 6.1
CVE-2017-16652 [MEDIUM] CVE-2017-16652 CVE-2018-11385 CVE-2018-11386 CVE-2018-11406 CVE-2018-11407 CVE-2018-11408 php-symfony: Multiple flaws
CVE-2017-16652 CVE-2018-11385 CVE-2018-11386 CVE-2018-11406 CVE-2018-11407 CVE-2018-11408 php-symfony: Multiple flaws
Multiple flaws in php-symfony.
References:
https://symfony.com/blog/category/security-advisories
Multiple versions affected.
Discussion:
Created php-symfony tracking bugs for this issue:
Affects: epel-all [bug 1591302]
Affects: fedora-all [bug 1591303]
---
(In reply to Pedro Sampaio from comment #0)
> Multiple flaws fixed in symfony 5.3.2
>
> References:
>
> https://blog.phusion.nl/2018/06/12/passenger-5-3-2-various-security-fixes/
>
> Ps. Some of the CVEs were not fixed in this release.
The reference points to Passenger 5.3.2 security advisory that talks about CVE-2018-12029 "CHMOD race vulnerability". This has nothing to do with the Symfony issues.
All Symfony
https://blog.phusion.nl/passenger-5-3-2https://lists.debian.org/debian-lts-announce/2018/06/msg00007.htmlhttps://pulsesecurity.co.nz/advisories/phusion-passenger-priv-eschttps://security.gentoo.org/glsa/201807-02https://blog.phusion.nl/passenger-5-3-2https://lists.debian.org/debian-lts-announce/2018/06/msg00007.htmlhttps://pulsesecurity.co.nz/advisories/phusion-passenger-priv-eschttps://security.gentoo.org/glsa/201807-02
2018-06-17
Published