~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2018-12028

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2018-12028
2
 
PublicDate: 2018-06-17
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12028
5
 
 https://blog.phusion.nl/2018/06/12/passenger-5-3-2-various-security-fixes/
6
 
 https://blog.phusion.nl/passenger-5-3-2
7
 
Description:
8
 
 An Incorrect Access Control vulnerability in SpawningKit in Phusion
9
 
 Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious
10
 
 application, upon spawning a child process, to report an arbitrary
11
 
 different PID back to Passenger's process manager. If the malicious
12
 
 application then generates an error, it would cause Passenger's process
13
 
 manager to kill said reported arbitrary PID.
14
 
Ubuntu-Description:
15
 
Notes:
16
 
Bugs:
17
 
Priority: medium
18
 
Discovered-by:
19
 
Assigned-to:
20
 
 
21
 
 
22
 
Patches_passenger:
23
 
upstream_passenger: needs-triage
24
 
precise/esm_passenger: DNE
25
 
trusty_passenger: DNE
26
 
xenial_passenger: needs-triage
27
 
artful_passenger: needs-triage
28
 
bionic_passenger: needs-triage
29
 
devel_passenger: needs-triage
30
 
 
31
 
Patches_ruby-passenger:
32
 
upstream_ruby-passenger: needs-triage
33
 
precise/esm_ruby-passenger: DNE
34
 
trusty_ruby-passenger: needs-triage
35
 
xenial_ruby-passenger: DNE
36
 
artful_ruby-passenger: DNE
37
 
bionic_ruby-passenger: DNE
38
 
devel_ruby-passenger: DNE