shield
Security update for rubygem-passenger
SUSE-SLE-Module-Containers-12-2018-182
This update for rubygem-passenger fixes several issues. These security issues were fixed: - CVE-2017-16355: When Passenger was running as root it was possible to list the contents of arbitrary files on a system by symlinking a file named REVISION from the application root folder to a file of choice and querying passenger-status --show=xml (bsc#1073255). - CVE-2017-1000384: Introduces a new check that logs a vulnerability warning if Passenger is run with root permissions while the directory permissions of (parts of) its root dir allow modifications by non-root users (bsc#1068874).
-
Release DateJan 29 2018
-
References
-
Typesecurity
-
Severitymoderate
cloud_download Downloads
Containers Module 12 x86_64
-
Packagesruby2.1-rubygem-passenger
A fast and robust web server and application server for Ruby, Pythonrubygem-passenger5.0.18-12.5.1 lock rpm
A fast and robust web server and application server for Ruby, Pythonrubygem-passenger-apache25.0.18-12.5.1 lock rpm lock src
Passenger apache module5.0.18-12.5.1 lock rpm