CVE-2014-1831 REJECTED

Phusion Passenger before 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file.

EPSS 0.07% · 20.6th percentile

Risk Scores

EPSS Score
0.07%
20.6th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSruby-passenger0, 3.0.13debian-1.2, 4.0.25-1

Timeline

References

Open in Interactive Console →