CVE-2007-1741
published 2007-04-13CVE-2007-1741: Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain…
PriorityP422medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.52%
40.5th percentile
Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| debian | apache2 | < apache2 2.2.8-5 (bookworm) | apache2 2.2.8-5 (bookworm) |
CVSS provenance
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
osv6.2MEDIUM
vendor_debian6.2LOW
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g8qp-hfrh-h336: Multiple race conditions in suexec in Apache HTTP Server (httpd) 2
ghsa_unreviewed·2022-05-01
CVE-2007-1741 [MEDIUM] CWE-362 GHSA-g8qp-hfrh-h336: Multiple race conditions in suexec in Apache HTTP Server (httpd) 2
Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
OSV
CVE-2007-1741: Multiple race conditions in suexec in Apache HTTP Server (httpd) 2
osv·2007-04-13·CVSS 6.2
CVE-2007-1741 [MEDIUM] CVE-2007-1741: Multiple race conditions in suexec in Apache HTTP Server (httpd) 2
Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
Debian
CVE-2007-1741: apache2 - Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between d...
vendor_debian·2007·CVSS 6.2
CVE-2007-1741 [MEDIUM] CVE-2007-1741: apache2 - Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between d...
Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
Scope: local
bookworm: resolved (fixed in 2.2.8-5)
bullseye: resolved (fixed in 2.2.8-5)
forky: resolved (fixed in 2.2.8-5)
sid: resolved (fixed in 2.2.8-5)
trixie: resolved (fixed in 2.2.8-5)
Red Hat
CVE-2007-1741: Multiple race conditions in suexec in Apache HTTP Server (httpd) 2
vendor_redhat·CVSS 6.2
CVE-2007-1741 [MEDIUM] CVE-2007-1741: Multiple race conditions in suexec in Apache HTTP Server (httpd) 2
Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
Statement: These attacks are reliant on an insecure configuration of the server - that the user the server runs as has write access to the document root. The suexec security model is not intented to protect against privilege escalation in such a configuration
No detection rules found.
No public exploits indexed.
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=511http://marc.info/?l=apache-httpd-dev&m=117511568709063&w=2http://marc.info/?l=apache-httpd-dev&m=117511834512138&w=2http://osvdb.org/38639http://www.securityfocus.com/bid/23438http://www.securitytracker.com/id?1017904https://exchange.xforce.ibmcloud.com/vulnerabilities/33584http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=511http://marc.info/?l=apache-httpd-dev&m=117511568709063&w=2http://marc.info/?l=apache-httpd-dev&m=117511834512138&w=2http://osvdb.org/38639http://www.securityfocus.com/bid/23438http://www.securitytracker.com/id?1017904https://exchange.xforce.ibmcloud.com/vulnerabilities/33584
2007-04-13
Published