CVE-2011-1176
published 2011-03-29CVE-2011-1176: The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not…
PriorityP429medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.72%
84.4th percentile
The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | apache2 | < apache2 2.2.17-2 (bookworm) | apache2 2.2.17-2 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| mpm-itk_project | mpm-itk | — | — |
| mpm-itk_project | mpm-itk | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8jf9-2rj5-99gg: The configuration merger in itk
ghsa_unreviewed·2022-05-13
CVE-2011-1176 [MEDIUM] GHSA-8jf9-2rj5-99gg: The configuration merger in itk
The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.
OSV
CVE-2011-1176: The configuration merger in itk
osv·2011-03-29·CVSS 4.3
CVE-2011-1176 [MEDIUM] CVE-2011-1176: The configuration merger in itk
The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.
Ubuntu
Apache vulnerabilities
vendor_ubuntu·2011-11-11·CVSS 4.3
CVE-2011-1176 [MEDIUM] Apache vulnerabilities
Title: Apache vulnerabilities
Summary: Multiple vulnerabilities and a regression were fixed in the Apache HTTP
server.
It was discovered that the mod_proxy module in Apache did not properly
interact with the RewriteRule and ProxyPassMatch pattern matches
in the configuration of a reverse proxy. This could allow remote
attackers to contact internal webservers behind the proxy that were
not intended for external exposure. (CVE-2011-3368)
Stefano Nichele discovered that the mod_proxy_ajp module in Apache when
used with mod_proxy_balancer in certain configurations could allow
remote attackers to cause a denial of service via a malformed HTTP
request. (CVE-2011-3348)
Samuel Montosa discovered that the ITK Multi-Processing Module for
Apache did not properly handle certain configuration secti
Debian
CVE-2011-1176: apache2 - The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Proc...
vendor_debian·2011·CVSS 4.3
CVE-2011-1176 [MEDIUM] CVE-2011-1176: apache2 - The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Proc...
The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.
Scope: local
bookworm: resolved (fixed in 2.2.17-2)
bullseye: resolved (fixed in 2.2.17-2)
forky: resolved (fixed in 2.2.17-2)
sid: resolved (fixed in 2.2.17-2)
trixie: resolved (fixed in 2.2.17-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=618857http://lists.err.no/pipermail/mpm-itk/2011-March/000393.htmlhttp://lists.err.no/pipermail/mpm-itk/2011-March/000394.htmlhttp://openwall.com/lists/oss-security/2011/03/20/1http://openwall.com/lists/oss-security/2011/03/21/13http://www.debian.org/security/2011/dsa-2202http://www.mandriva.com/security/advisories?name=MDVSA-2011:057http://www.securityfocus.com/bid/46953http://www.vupen.com/english/advisories/2011/0748http://www.vupen.com/english/advisories/2011/0749http://www.vupen.com/english/advisories/2011/0824https://exchange.xforce.ibmcloud.com/vulnerabilities/66248http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=618857http://lists.err.no/pipermail/mpm-itk/2011-March/000393.htmlhttp://lists.err.no/pipermail/mpm-itk/2011-March/000394.htmlhttp://openwall.com/lists/oss-security/2011/03/20/1http://openwall.com/lists/oss-security/2011/03/21/13http://www.debian.org/security/2011/dsa-2202http://www.mandriva.com/security/advisories?name=MDVSA-2011:057http://www.securityfocus.com/bid/46953http://www.vupen.com/english/advisories/2011/0748http://www.vupen.com/english/advisories/2011/0749http://www.vupen.com/english/advisories/2011/0824https://exchange.xforce.ibmcloud.com/vulnerabilities/66248
2011-03-29
Published