MGASA-2013-0253
Dashboard / Vulnerabilities / MGASA-2013-0253
Summary: Updated rubygem-passenger package fixes CVE-2013-4136 & apache module
Details: Updated rubygem-passenger package fixes security vulnerability: It was reported that Phusion Passenger would reuse existing server instance directories (temporary directories) which could cause Passenger to remove or overwrite files belonging to other instances (CVE-2013-4136). Additionally, the package has been fixed so that the Apache module should load.
References: https://advisories.mageia.org/MGASA-2013-0253.html, https://lists.fedoraproject.org/pipermail/package-announce/2013-July/112716.html, https://bugs.mageia.org/show_bug.cgi?id=10890
Affected packages
Package
Name: rubygem-passenger
Purl: pkg:rpm/mageia/rubygem-passenger?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
