CVE Vulnerabilities

CVE-2014-8583

Published: Dec 16, 2014 | Modified: Jul 01, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
6.9 MODERATE
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM

mod_wsgi before 4.2.4 for Apache, when creating a daemon process group, does not properly handle when group privileges cannot be dropped, which might allow attackers to gain privileges via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Mod_wsgi Modwsgi * 4.2.4 (including)
Mod-wsgi Ubuntu lucid *
Mod-wsgi Ubuntu precise *
Mod-wsgi Ubuntu trusty *
Mod-wsgi Ubuntu upstream *
Mod-wsgi Ubuntu utopic *

References