mod_wsgi before 4.2.4 for Apache, when creating a daemon process group, does not properly handle when group privileges cannot be dropped, which might allow attackers to gain privileges via unspecified vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mod_wsgi | Modwsgi | * | 4.2.4 (including) |
Mod-wsgi | Ubuntu | lucid | * |
Mod-wsgi | Ubuntu | precise | * |
Mod-wsgi | Ubuntu | trusty | * |
Mod-wsgi | Ubuntu | upstream | * |
Mod-wsgi | Ubuntu | utopic | * |