CVE-2011-1176
Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by…
Does this matter?
Lower severity and a low EPSS score (2.72%). Track it; it rarely justifies an emergency change on its own.
Description
The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.72% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- mpm-itk project/mpm-itk · debian/debian linux
- Source
- secalert@redhat.com
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=618857Issue Tracking, Patch, Third Party Advisory
- http://lists.err.no/pipermail/mpm-itk/2011-March/000393.htmlPatch, Third Party Advisory
- http://lists.err.no/pipermail/mpm-itk/2011-March/000394.htmlRelease Notes, Third Party Advisory
- http://openwall.com/lists/oss-security/2011/03/20/1Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2011/03/21/13Mailing List, Third Party Advisory
- http://www.debian.org/security/2011/dsa-2202Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:057Third Party Advisory
- http://www.securityfocus.com/bid/46953Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2011/0748Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0749Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0824Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66248Third Party Advisory, VDB Entry
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=618857Issue Tracking, Patch, Third Party Advisory
- http://lists.err.no/pipermail/mpm-itk/2011-March/000393.htmlPatch, Third Party Advisory
- http://lists.err.no/pipermail/mpm-itk/2011-March/000394.htmlRelease Notes, Third Party Advisory
- http://openwall.com/lists/oss-security/2011/03/20/1Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2011/03/21/13Mailing List, Third Party Advisory
- http://www.debian.org/security/2011/dsa-2202Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:057Third Party Advisory
- http://www.securityfocus.com/bid/46953Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2011/0748Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0749Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0824Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66248Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.