Ruby Phusion Passenger 'server instance directory' Insecure Temporary File Creation Vulnerability
BID:65207
Info
Ruby Phusion Passenger 'server instance directory' Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 65207 |
| Class: | Design Error |
| CVE: |
CVE-2014-1831 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 29 2014 12:00AM |
| Updated: | Feb 04 2014 01:57AM |
| Credit: | Jakub Wilk |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Ruby Phusion Passenger 'server instance directory' Insecure Temporary File Creation Vulnerability
Phusion Passenger gem for Ruby is prone to a vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks.
Successfully mounting a symlink attack may allow the attacker to corrupt sensitive files or gain access to sensitive information. Other attacks may also be possible.
Phusion Passenger gem for Ruby is prone to a vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks.
Successfully mounting a symlink attack may allow the attacker to corrupt sensitive files or gain access to sensitive information. Other attacks may also be possible.
Exploit / POC
Ruby Phusion Passenger 'server instance directory' Insecure Temporary File Creation Vulnerability
An attacker can use readily available commands to exploit this issue.
An attacker can use readily available commands to exploit this issue.
Solution / Fix
Ruby Phusion Passenger 'server instance directory' Insecure Temporary File Creation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Ruby Phusion Passenger 'server instance directory' Insecure Temporary File Creation Vulnerability
References:
References: