{
  "schema_version": "1.7.0",
  "id": "MGASA-2013-0205",
  "published": "2013-07-09T18:27:49Z",
  "modified": "2013-07-09T18:26:08Z",
  "summary": "Updated rubygem-passenger package fixes CVE-2013-2119",
  "details": "Phusion Passengers code did not always create temporary files and directories\nin a secure manner. Temporary files and directories were sometimes created\nwith a predictable filename. A local attacker can pre-create temporary files,\nresulting in a denial of service. In addition, this vulnerability allows a\nlocal attacker to run arbitrary code as another user, by hijacking temporary\nfiles (CVE-2013-2119).\n\nThe rubygem-passenger package has been upgraded to version 3.0.21, which fixes\nthis issue, as well as many others although at the moment has further issues \nwhich will be fixed with another update (mga#10728).\n",
  "upstream": [
    "CVE-2013-2119"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2013-0205.html"
    },
    {
      "type": "WEB",
      "url": "http://blog.phusion.nl/2013/05/29/phusion-passenger-3-0-21-released/"
    },
    {
      "type": "WEB",
      "url": "http://blog.phusion.nl/2013/05/29/phusion-passenger-4-0-5-released/"
    },
    {
      "type": "WEB",
      "url": "https://lists.fedoraproject.org/pipermail/package-announce/2013-June/108443.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=10728"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=10497"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:3",
        "name": "rubygem-passenger",
        "purl": "pkg:rpm/mageia/rubygem-passenger?arch=source&distro=mageia-3"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "3.0.21-2.mga3"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
