CVE-2018-12027
Summary
| CVE | CVE-2018-12027 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-17 20:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the parent directories of said socket are writable by a normal user that is not the application's user, then that non-application user can swap that directory with something else, resulting in traffic being redirected to a non-application user's process through an alternative Unix domain socket. |
Risk And Classification
Problem Types: CWE-200 | CWE-732
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Passenger 5.3.2: various security fixes | MISC | blog.phusion.nl | Mitigation, Vendor Advisory |
| Passenger: Multiple Vulnerabilities (GLSA 201807-02) — Gentoo security | GENTOO | security.gentoo.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710280 Gentoo Linux Passenger Multiple Vulnerabilities (GLSA 201807-02)