FlawAtlas
Search the atlas
SUSE-SU-2016:0042-1 Not scored

Security update for rubygem-passenger

This update fixes the following security issues: - CVE-2015-7519: Passenger is not filtering environment like apache is doing (bnc#956281) - CVE-2013-4136: Fixed security issue Passenger would reuse existing server instance directories (temporary directories) which could cause Passenger to remove or overwrite files belonging to other instances. Solution: If the server instance directory already exists, it will now be removed first in order get correct directory permissions. If the directory still exists after removal, Phusion Passenger aborts to avoid writing to a directory with unexpected permissions.(bnc#919726) - CVE-2013-2119: Fixed security issue related with incorrect temporary file usage (bnc#828005)

Exploit probability Not scored
Published January 7, 2016
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Lifecycle Management Server 1.3 rubygem-passenger
SUSE:Studio Onsite 1.3 rubygem-passenger
SUSE:WebYast 1.3 rubygem-passenger

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2016:0042-1

This update fixes the following security issues: - CVE-2015-7519: Passenger is not filtering environment like apache is doing (bnc#956281) - CVE-2013-4136: Fixed security issue Passenger would reuse existing server instance directories (temporary directories) which could cause Passenger to remove or overwrite files belonging to other instances. Solution: If the server instance directory already exists, it will now be removed first in order get correct directory permissions. If the directory still exists after removal, Phusion Passenger aborts to avoid writing to a directory with unexpected permissions.(bnc#919726) - CVE-2013-2119: Fixed security issue related with incorrect temporary file usage (bnc#828005)

View original source

05 / REFERENCES

Further evidence