VYPR
Moderate severityNVD Advisory· Published Sep 30, 2013· Updated Jun 16, 2026

CVE-2013-4136

CVE-2013-4136

Description

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
passengerRubyGems
< 4.0.64.0.6

Affected products

9

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.