{"schema_version":"1.9.0","id":"GHSA-9qj7-jvg4-qr2x","published":"2017-10-24T18:33:37Z","modified":"2024-12-08T05:23:50.219453Z","aliases":["CVE-2013-2119"],"summary":"Phusion Passenger Denial of Service","details":"Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary \"config\" file in a directory with a predictable name in `/tmp/` before it is used by the gem.","affected":[{"package":{"name":"passenger","ecosystem":"RubyGems","purl":"pkg:gem/passenger"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.21"}]}],"versions":["1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.1.2","2.1.3","2.2.0","2.2.1","2.2.10","2.2.11","2.2.12","2.2.13","2.2.14","2.2.15","2.2.2","2.2.3","2.2.4","2.2.5","2.2.6","2.2.7","2.2.8","2.2.9","3.0.0","3.0.0.pre1","3.0.0.pre2","3.0.0.pre3","3.0.0.pre4","3.0.1","3.0.10","3.0.11","3.0.12","3.0.13","3.0.14","3.0.15","3.0.17","3.0.18","3.0.19","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-9qj7-jvg4-qr2x/GHSA-9qj7-jvg4-qr2x.json"}},{"package":{"name":"passenger","ecosystem":"RubyGems","purl":"pkg:gem/passenger"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.1"},{"fixed":"4.0.5"}]}],"versions":["4.0.1","4.0.2","4.0.3","4.0.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-9qj7-jvg4-qr2x/GHSA-9qj7-jvg4-qr2x.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-2119"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2013:1136"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2013-2119"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=892813"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9qj7-jvg4-qr2x"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/passenger/CVE-2013-2119.yml"},{"type":"WEB","url":"http://blog.phusion.nl/2013/05/29/phusion-passenger-3-0-21-released"},{"type":"WEB","url":"http://blog.phusion.nl/2013/05/29/phusion-passenger-4-0-5-released"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2013-1136.html"}],"database_specific":{"cwe_ids":["CWE-377"],"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:29:24Z","nvd_published_at":"2014-01-03T18:54:00Z","severity":"MODERATE"}}