SUSE-SU-2016:0042-1
Dashboard / Vulnerabilities / SUSE-SU-2016:0042-1
SUSE-SU-2016:0042-1
Summary: Security update for rubygem-passenger
Details: This update fixes the following security issues: - CVE-2015-7519: Passenger is not filtering environment like apache is doing (bnc#956281) - CVE-2013-4136: Fixed security issue Passenger would reuse existing server instance directories (temporary directories) which could cause Passenger to remove or overwrite files belonging to other instances. Solution: If the server instance directory already exists, it will now be removed first in order get correct directory permissions. If the directory still exists after removal, Phusion Passenger aborts to avoid writing to a directory with unexpected permissions.(bnc#919726) - CVE-2013-2119: Fixed security issue related with incorrect temporary file usage (bnc#828005)
References: https://www.suse.com/support/update/announcement/2016/suse-su-20160042-1/, https://bugzilla.suse.com/828005, https://bugzilla.suse.com/919726, https://bugzilla.suse.com/956281, https://www.suse.com/security/cve/CVE-2013-2119, https://www.suse.com/security/cve/CVE-2013-4136, https://www.suse.com/security/cve/CVE-2015-7519
Affected packages
Package
Name: rubygem-passenger
Purl: pkg:rpm/suse/rubygem-passenger&distro=SUSE%20Lifecycle%20Management%20Server%201.3
Affected ranges
Type: ECOSYSTEM
Events:
