CVE Database
/

CVE-2018-12026

Back to search

CVE-2018-12026

Published: Jun 17, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks. This then could result in arbitrary reads and writes, which in turn can result in information disclosure and privilege escalation.

VendorProductVersions

n/a

n/a

affected
n/a

References

GLSA-201807-02
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now