Index: head/security/vuxml/vuln.xml =================================================================== --- head/security/vuxml/vuln.xml +++ head/security/vuxml/vuln.xml @@ -58,6 +58,34 @@ * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + rubygem-passenger -- arbitrary file read vulnerability + + + rubygem-passenger + 5.0.105.1.11 + + + + +

Phusion reports:

+
+

The cPanel Security Team discovered a vulnerability in Passenger + that allows users to list the contents of arbitrary files on the + system. CVE-2017-16355 has been assigned to this issue.

+
+ +
+ + https://blog.phusion.nl/2017/10/13/passenger-security-advisory-5-1-11/ + CVE-2017-16355 + + + 2017-10-13 + 2017-12-18 + +
+ libXfont -- permission bypass when opening files through symlinks