CVE Database
/

CVE-2011-1176

Back to search

CVE-2011-1176

Published: Mar 29, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.

VendorProductVersions

n/a

n/a

affected
n/a

References

46953
vdb-entry
x_refsource_BID
MDVSA-2011:057
vendor-advisory
x_refsource_MANDRIVA
apache-mtmitk-weak-security(66248)
vdb-entry
x_refsource_XF
ADV-2011-0824
vdb-entry
x_refsource_VUPEN
ADV-2011-0748
vdb-entry
x_refsource_VUPEN
DSA-2202
vendor-advisory
x_refsource_DEBIAN
ADV-2011-0749
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now