Debian Security Update DSA-4415 passenger - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,838
Reaction score
74
Credits
-1,257
An arbitrary file read vulnerability was discovered in passenger, a web application server. A local user allowed to deploy an application to passenger, can take advantage of this flaw by creating a symlink from the REVISION file to an arbitrary file on the system and have its content displayed through passenger-status.

Continue reading...
 


Follow Linux.org

Staff online

Members online


Top