UBUNTU-CVE-2018-12027
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-12027
Summary:
Details: An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the parent directories of said socket are writable by a normal user that is not the application's user, then that non-application user can swap that directory with something else, resulting in traffic being redirected to a non-application user's process through an alternative Unix domain socket.
References: https://ubuntu.com/security/CVE-2018-12027, https://blog.phusion.nl/2018/06/12/passenger-5-3-2-various-security-fixes/, https://blog.phusion.nl/passenger-5-3-2, https://www.cve.org/CVERecord?id=CVE-2018-12027
Affected packages
Package
Name: passenger
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=jammy
Affected ranges
Type: ECOSYSTEM
Events:
