CVE-2013-4136

Phusion Passenger < 4.0.6 - Privilege Escalation via Symlink Attack on Predictable /tmp Directory

Title source: llm
STIX 2.1

Description

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

Scores

EPSS 0.0004
EPSS Percentile 13.6%

Details

CWE
CWE-59
Status published
Products (6)
phusion/passenger 4.0.1
phusion/passenger 4.0.2
phusion/passenger 4.0.3
phusion/passenger 4.0.4
phusion/passenger < 4.0.5
rubygems/passenger 0 - 4.0.6RubyGems
Published Sep 30, 2013
Tracked Since Feb 18, 2026