{"schema_version":"1.9.0","id":"GHSA-qw8w-2xcp-xg59","published":"2018-10-10T17:29:27Z","modified":"2023-11-08T03:57:34.943941Z","aliases":["CVE-2014-1832"],"summary":"Insecure use of temporary files in Phusion passenger","details":"Phusion Passenger 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1831.","affected":[{"package":{"name":"passenger","ecosystem":"RubyGems","purl":"pkg:gem/passenger"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.37"},{"fixed":"4.0.38"}]}],"versions":["4.0.37"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-qw8w-2xcp-xg59/GHSA-qw8w-2xcp-xg59.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-1832"},{"type":"WEB","url":"https://github.com/phusion/passenger/commit/94428057c602da3d6d34ef75c78091066ecac5c0"},{"type":"WEB","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=736958"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1058992"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-qw8w-2xcp-xg59"},{"type":"PACKAGE","url":"https://github.com/phusion/passenger"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/passenger/CVE-2014-1832.yml"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-February/149032.html"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2014/01/29/6"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2014/01/30/3"}],"database_specific":{"cwe_ids":[],"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:52:59Z","nvd_published_at":"2015-02-19T15:59:04Z","severity":"LOW"}}