FlawAtlas
Search the atlas
CVE-2013-4136 Moderate

CVE-2013-4136

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

Exploit probability 0.3%
Published September 30, 2013
Required by Not available
Last source change April 16, 2026

02 / AFFECTED SOFTWARE

Affected packages

RubyGems passenger

62 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2013-4136

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

View original source
Open Source Vulnerabilities GHSA-w6rc-q387-vpgq

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

View original source

05 / REFERENCES

Further evidence