CVE-2011-1176
Publication date 29 March 2011
Last updated 24 July 2024
Ubuntu priority
The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.
Status
Package | Ubuntu Release | Status |
---|---|---|
apache2 | ||
apache2-mpm-itk | ||
Notes
sbeattie
NOTE: mpm-itk patches go in debian/mpm-itk/patches hardy version predates introduction of configuration merger at all, so not-affected
References
Related Ubuntu Security Notices (USN)
- USN-1259-1
- Apache vulnerabilities
- 11 November 2011