Synced 30 Sept 2026 23:45 UTC Account
← All products

CVE-2013-2119

MEDIUM severity · CVSS 4.6 · CWE-264
4.6CVSS MEDIUM

Summary

Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.

Impact & exploitability

Attack vectorLocal
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)0%

AV:L/AC:L/Au:N/C:P/I:P/A:P

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.

Official patch: http://blog.phusion.nl/2013/05/29/phusion-passenger-3-0-21-released/ ↗