ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.
| Software | From | Fixed in |
|---|---|---|
| phusion / passenger | - | 4.0.5.x |
| phusion / passenger | 4.0.1 | 4.0.1.x |
| phusion / passenger | 4.0.2 | 4.0.2.x |
| phusion / passenger | 4.0.3 | 4.0.3.x |
| phusion / passenger | 4.0.4 | 4.0.4.x |
passenger
|
- | 4.0.6 |