passenger: File overwrite vulnerability in passenger-install-nginx-module
Published Apr 18, 2017
7.8
HIGHCVSS 3.0
EPSS 0.46%
Description
In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the passenger user.
Affected products
No data.
No data.
Red Hat Ceph Storage 1.3
ruby193-rubygem-passenger
Not affected
Red Hat Ceph Storage 1.3
rubygem-passenger
Not affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installer
ruby193-rubygem-passenger
Will not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installer
rubygem-passenger
Will not fix
Red Hat OpenShift Enterprise 2
ruby-193-rubygem-passenger
Will not fix
Red Hat OpenShift Enterprise 2
ruby200-rubygem-passenger
Will not fix
Red Hat OpenShift Enterprise 2
rubygem-passenger
Will not fix
Red Hat Satellite 6
ruby193-rubygem-passenger
Not affected
Red Hat Satellite 6
rubygem-passenger
Not affected
Red Hat Software Collections
rh-passenger40-passenger
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 1.3 | ruby193-rubygem-passenger | Not affected | n/a |
| Red Hat Ceph Storage 1.3 | rubygem-passenger | Not affected | n/a |
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installer | ruby193-rubygem-passenger | Will not fix | n/a |
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installer | rubygem-passenger | Will not fix | n/a |
| Red Hat OpenShift Enterprise 2 | ruby-193-rubygem-passenger | Will not fix | n/a |
| Red Hat OpenShift Enterprise 2 | ruby200-rubygem-passenger | Will not fix | n/a |
| Red Hat OpenShift Enterprise 2 | rubygem-passenger | Will not fix | n/a |
| Red Hat Satellite 6 | ruby193-rubygem-passenger | Not affected | n/a |
| Red Hat Satellite 6 | rubygem-passenger | Not affected | n/a |
| Red Hat Software Collections | rh-passenger40-passenger | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
AV:L/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.46% (0.00464) | 37.87th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.46% (0.00464) | 36.43th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.09% (0.00087) | 22.78th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 15.20th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.04% (0.00042) | 5.47th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00044) | 10.97th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.10% (0.01102) | 53.65th | v2 (v2022.01.01) |
| Sep 15, 2022 | 1.10% (0.01102) | 51.95th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.10% (0.01102) | 49.95th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.10% (0.01102) | 28.50th | v2 (v2022.01.01) |
References (9)
- https://access.redhat.com/security/cve/CVE-2016-10345 Vendor Advisory
- https://blog.phusion.nl/2017/01/10/passenger-5-1-1/
- https://bugzilla.redhat.com/show_bug.cgi?id=1445306 Issue Tracking
- https://github.com/advisories/GHSA-cqxw-3p7v-p9gr Advisory
- https://github.com/phusion/passenger/blob/stable-5.1/CHANGELOG x_refsource_CONFIRMPatchRelease Notes
- https://github.com/phusion/passenger/commit/e5b4b0824d6b648525b4bf63d9fa37e5beeae441 x_refsource_CONFIRMPatch
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/passenger/CVE-2016-10345.yml
- https://nvd.nist.gov/vuln/detail/CVE-2016-10345
- https://www.cve.org/CVERecord?id=CVE-2016-10345
Change history (0)
No recorded changes yet.