Multiple race conditions in suexec in Apache HTTP Server (httpd)...
Vulnerability Description
Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-1741
Credits & Attribution
No credits recorded in the NVD database.
References
- http://osvdb.org/38639
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=511
- http://marc.info/?l=apache-httpd-dev&m=117511834512138&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33584
- http://www.securitytracker.com/id?1017904
- http://www.securityfocus.com/bid/23438
- http://marc.info/?l=apache-httpd-dev&m=117511568709063&w=2
More from apache
View All →Affected Vendor
apache
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.