CVE-2018-12028
Summary
| CVE | CVE-2018-12028 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-17 20:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to report an arbitrary different PID back to Passenger's process manager. If the malicious application then generates an error, it would cause Passenger's process manager to kill said reported arbitrary PID. |
Risk And Classification
Problem Types: CWE-732
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Passenger 5.3.2: various security fixes | MISC | blog.phusion.nl | Mitigation, Vendor Advisory |
| Passenger: Multiple Vulnerabilities (GLSA 201807-02) — Gentoo security | GENTOO | security.gentoo.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710280 Gentoo Linux Passenger Multiple Vulnerabilities (GLSA 201807-02)