Bug 917925 (CVE-2012-6135)
Summary: | CVE-2012-6135 rubygem-passenger: untrusted apps Security check socket filenames reported by spawned application processes | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Kurt Seifried <kseifried> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED NOTABUG | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | bkabrda, bleanhar, brett.lentz, ccoleman, dmcphers, honglilai, jialiu, lmeyer, mmcgrath, tdawson, vanmeeuwen+fedora |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2014-06-27 19:52:53 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 917928, 917930, 917931, 917932 | ||
Bug Blocks: | 917927 |
Description
Kurt Seifried
2013-03-05 06:52:53 UTC
Created rubygem-passenger tracking bugs for this issue Affects: epel-6 [bug 917928] Created rubygem-passenger tracking bugs for this issue Affects: fedora-all [bug 917930] We've released a security advisory here: http://blog.phusion.nl/2013/03/05/phusion-passenger-4-0-beta-1-and-2-arbitrary-file-deletion-vulnerability/ Affected versions: Phusion Passenger open source 4.0.0 beta 1 Phusion Passenger open source 4.0.0 beta 2 Phusion Passenger Enterprise 4.0.0 beta 1 Phusion Passenger Enterprise 4.0.0 beta 2 Unaffected versions: Phusion Passenger open source 3.x and earlier Phusion Passenger open source 4.0.0 RC 1 and later Phusion Passenger Enterprise 3.x and earlier Phusion Passenger Enterprise 4.0.0 RC 1 and later Statement: Not vulnerable. This issue did not affect the versions of rubygem-passenger as shipped with Red Hat OpenShift Enterprise 1.2 do not include the vulnerable code. |