ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.
Exploitability
AV:LAC:MAu:NImpact
C:PI:PA:P4.4/AV:L/AC:M/Au:N/C:P/I:P/A:P