PT-2007-3106 · Apache · Apache Http Server
Published
2007-04-13
·
Updated
2017-07-29
·
CVE-2007-1741
CVSS v2.0
6.2
Medium
| Vector | AV:L/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Apache HTTP Server (httpd) version 2.2.3
Description:
The issue involves multiple race conditions in suexec, allowing local users to gain privileges and execute arbitrary code. This can be achieved by renaming directories or performing symlink attacks. It's noted that the attacks rely on an insecure server configuration where the user has write access to the document root.
Recommendations:
For Apache HTTP Server (httpd) version 2.2.3, consider restricting write access to the document root to minimize the risk of exploitation. As a temporary workaround, review and secure server configurations to prevent users from having unnecessary write access, which could mitigate the risk associated with this issue.
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Http Server