Vulnerability Name: | CVE-2014-1832 (CCN-90874) | ||||||||||||||||
Assigned: | 2014-01-29 | ||||||||||||||||
Published: | 2014-01-29 | ||||||||||||||||
Updated: | 2015-02-20 | ||||||||||||||||
Summary: | Phusion Passenger 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file. Note: this vulnerability exists because of an incomplete fix for CVE-2014-1831. CWE-61: UNIX Symbolic Link (Symlink) Following | ||||||||||||||||
CVSS v3 Severity: | 5.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N) 1.8 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
2.9 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | File Manipulation | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-1832 Source: FEDORA Type: UNKNOWN FEDORA-2015-1151 Source: MLIST Type: UNKNOWN [oss-security] 20140129 Re: CVE request: temporary file issue in Passenger rubygem Source: MLIST Type: UNKNOWN [oss-security] 20150130 Re: CVE request: temporary file issue in Passenger rubygem Source: CCN Type: RubyGems Web site Phusion Passenger gem for Ruby Source: CCN Type: SA56617 Ruby Phusion Passenger Gem Temporary Directory Creation Race Condition Security Issue Source: CCN Type: oss-security: Wed, 29 Jan 2014 Re: CVE request: temporary file issue in Passenger rubygem Source: CCN Type: BID-65267 Ruby Phusion Passenger CVE-2014-1832 Incomplete Fix Insecure Temporary File Creation Vulnerability Source: CONFIRM Type: UNKNOWN https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=736958 Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=1058992 Source: XF Type: UNKNOWN phusion-passenger-cve20141832-symlink(90874) Source: CONFIRM Type: UNKNOWN https://github.com/phusion/passenger/commit/94428057c602da3d6d34ef75c78091066ecac5c0 Source: CCN Type: WhiteSource Vulnerability Database CVE-2014-1832 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |