CVE Vulnerabilities

CVE-2014-0240

Published: May 27, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.2 MEDIUM
AV:L/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
6.9 IMPORTANT
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by setuid when run on certain Linux kernels, which allows local users to gain privileges via vectors related to the number of running processes.

Affected Software

NameVendorStart VersionEnd Version
Mod_wsgiModwsgi*3.4 (including)
Mod_wsgiModwsgi1.0 (including)1.0 (including)
Mod_wsgiModwsgi1.1 (including)1.1 (including)
Mod_wsgiModwsgi1.2 (including)1.2 (including)
Mod_wsgiModwsgi1.3 (including)1.3 (including)
Mod_wsgiModwsgi1.4 (including)1.4 (including)
Mod_wsgiModwsgi1.5 (including)1.5 (including)
Mod_wsgiModwsgi1.6 (including)1.6 (including)
Mod_wsgiModwsgi2.0 (including)2.0 (including)
Mod_wsgiModwsgi2.1 (including)2.1 (including)
Mod_wsgiModwsgi2.2 (including)2.2 (including)
Mod_wsgiModwsgi2.3 (including)2.3 (including)
Mod_wsgiModwsgi2.4 (including)2.4 (including)
Mod_wsgiModwsgi2.5 (including)2.5 (including)
Mod_wsgiModwsgi2.6 (including)2.6 (including)
Mod_wsgiModwsgi2.7 (including)2.7 (including)
Mod_wsgiModwsgi2.8 (including)2.8 (including)
Mod_wsgiModwsgi3.0 (including)3.0 (including)
Mod_wsgiModwsgi3.1 (including)3.1 (including)
Mod_wsgiModwsgi3.2 (including)3.2 (including)
Mod_wsgiModwsgi3.3 (including)3.3 (including)
Red Hat Enterprise Linux 6RedHatmod_wsgi-0:3.2-6.el6_5*
Red Hat Enterprise Linux 7RedHatmod_wsgi-0:3.4-12.el7_0*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6RedHatpython27-mod_wsgi-0:3.4-12.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6RedHatpython33-mod_wsgi-0:3.4-14.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.3 EUSRedHatpython27-mod_wsgi-0:3.4-12.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.3 EUSRedHatpython33-mod_wsgi-0:3.4-14.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUSRedHatpython27-mod_wsgi-0:3.4-12.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUSRedHatpython33-mod_wsgi-0:3.4-14.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7RedHatpython27-mod_wsgi-0:3.4-13.el7*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7RedHatpython33-mod_wsgi-0:3.4-13.el7*
Mod-wsgiUbuntudevel*
Mod-wsgiUbuntuesm-infra-legacy/trusty*
Mod-wsgiUbuntulucid*
Mod-wsgiUbuntuprecise*
Mod-wsgiUbuntusaucy*
Mod-wsgiUbuntutrusty*
Mod-wsgiUbuntutrusty/esm*
Mod-wsgiUbuntuupstream*

References