Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-1176

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2011-1176
Last Modified 06 Sep 2011 11:15:33
Published 29 Mar 2011 02:55:02
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2011-1176

Summary

The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.

Vulnerable Systems

Application

  • Steinar H Gunderson Mpm-itk 2.2.11-01

  • Steinar H Gunderson Mpm-itk 2.2.11-02


References

MLIST - [oss-security] 20110321 Re: CVE request: MPM-ITK module for Apache HTTPD

MLIST - [oss-security] 20110320 CVE request: MPM-ITK module for Apache HTTPD

MLIST - [mpm-itk] 20110321 CVE 2011-1176: Sometimes runs as root instead of the default Apache user

CONFIRM - http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=618857

XF - apache-mtmitk-weak-security(66248)

VUPEN - ADV-2011-0824

VUPEN - ADV-2011-0749

VUPEN - ADV-2011-0748

BID - 46953

MANDRIVA - MDVSA-2011:057

DEBIAN - DSA-2202

MLIST - [mpm-itk] 20110321 mpm-itk version 2.2.17-01 released


Last Updated: 27 May 2016 10:56:12