CVE-2014-0240
Publication date 23 May 2014
Last updated 24 July 2024
Ubuntu priority
The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by setuid when run on certain Linux kernels, which allows local users to gain privileges via vectors related to the number of running processes.
Status
Package | Ubuntu Release | Status |
---|---|---|
mod-wsgi | 14.04 LTS trusty |
Fixed 3.4-4ubuntu2.1.14.04.1
|
Notes
mdeslaur
from upstream: The issue is believed to affect Linux systems running kernel versions >= 2.6.0 and < 3.1.0.
References
Related Ubuntu Security Notices (USN)
- USN-2222-1
- mod_wsgi vulnerabilities
- 26 May 2014