CVE Vulnerabilities

CVE-2014-8583

Published: Dec 16, 2014 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
6.9 MODERATE
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM

mod_wsgi before 4.2.4 for Apache, when creating a daemon process group, does not properly handle when group privileges cannot be dropped, which might allow attackers to gain privileges via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Mod_wsgi Modwsgi * 4.2.4 (including)
Mod-wsgi Ubuntu lucid *
Mod-wsgi Ubuntu precise *
Mod-wsgi Ubuntu trusty *
Mod-wsgi Ubuntu upstream *
Mod-wsgi Ubuntu utopic *

References