passenger: CHMOD race condition in nginx_module/ngx_http_passenger_module.c allows for local privilege escalation
Published Jun 17, 2018
7.8
HIGHCVSS 3.0
EPSS 0.28%
Description
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but before it was chowned, leads to the target of the link being chowned via the path. Targeting sensitive files such as root's crontab file allows privilege escalation.
Affected products
No data.
Configuration 2
- 8.0
No data.
Red Hat Ceph Storage 1.3
rubygem-passenger
Will not fix
Red Hat Satellite 6
rubygem-passenger
Not affected
Red Hat Update Infrastructure 3 for Cloud Providers
rubygem-passenger
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 1.3 | rubygem-passenger | Will not fix | n/a |
| Red Hat Satellite 6 | rubygem-passenger | Not affected | n/a |
| Red Hat Update Infrastructure 3 for Cloud Providers | rubygem-passenger | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- https://access.redhat.com/security/cve/CVE-2018-12029 Vendor Advisory
- https://blog.phusion.nl/2018/06/12/passenger-5-3-2-various-security-fixes/
- https://blog.phusion.nl/passenger-5-3-2 x_refsource_MISCMitigationVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1592612 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4382 Advisory
- https://github.com/advisories/GHSA-jjcj-fgfm-9g9r Advisory
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/passenger/CVE-2018-12029.yml
- https://lists.debian.org/debian-lts-announce/2018/06/msg00007.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-12029
- https://pulsesecurity.co.nz/advisories/phusion-passenger-priv-esc x_refsource_MISCThird Party Advisory
- https://security.gentoo.org/glsa/201807-02 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-12029
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-12029 | Vendor Advisory | |
| https://blog.phusion.nl/2018/06/12/passenger-5-3-2-various-security-fixes/ | ||
| https://blog.phusion.nl/passenger-5-3-2 | x_refsource_MISCMitigationVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1592612 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4382 | Advisory | |
| https://github.com/advisories/GHSA-jjcj-fgfm-9g9r | Advisory | |
| https://github.com/rubysec/ruby-advisory-db/blob/master/gems/passenger/CVE-2018-12029.yml | ||
| https://lists.debian.org/debian-lts-announce/2018/06/msg00007.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-12029 | ||
| https://pulsesecurity.co.nz/advisories/phusion-passenger-priv-esc | x_refsource_MISCThird Party Advisory | |
| https://security.gentoo.org/glsa/201807-02 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2018-12029 |
Change history (0)
No recorded changes yet.