CVE Vulnerabilities

CVE-2011-1176

Published: Mar 29, 2011 | Modified: Nov 16, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.

Affected Software

Name Vendor Start Version End Version
Mpm-itk Mpm-itk_project 2.2.11-01 (including) 2.2.11-01 (including)
Mpm-itk Mpm-itk_project 2.2.11-02 (including) 2.2.11-02 (including)
Apache2 Ubuntu karmic *
Apache2 Ubuntu lucid *
Apache2 Ubuntu maverick *
Apache2 Ubuntu natty *

References