LWN.net Logo

rubygem-passenger: insecure temporary directory usage

Package(s):rubygem-passenger CVE #(s):CVE-2013-4136
Created:July 31, 2013 Updated:August 23, 2013
Description: From the Red Hat bugzilla:

It was reported [1],[2] that Phusion Passenger would reuse existing server instance directories (temporary directories) which could cause Passenger to remove or overwrite files belonging to other instances. This has been corrected in upstream version 4.0.8 via two fixes (the initial fix and a regression fix; both are required to fully fix the issue). This is an issue similar to CVE-2013-2119.

Alerts:
Fedora FEDORA-2013-13231 2013-07-30
Fedora FEDORA-2013-13234 2013-07-30
Fedora FEDORA-2013-13297 2013-07-30
Red Hat RHSA-2013:1136-01 2013-08-05
Mageia MGASA-2013-0253 2013-08-22

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds