CVE-2012-0883Apache Http Server vulnerability

7 documents7 sources
Severity
6.9MEDIUMNVD
EPSS
0.2%
top 58.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 18
Latest updateMay 13

Description

envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages2 packages

NVDapache/http_server2.2.02.2.23+1
NVDopensuse/opensuse11.4, 12.1+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gmh7-j6pc-xmxr: envvars (aka envvars-std) in the Apache HTTP Server before 22022-05-13
CVEList
CVE-2012-0883: envvars (aka envvars-std) in the Apache HTTP Server before 22012-04-18

📋Vendor Advisories

3
Red Hat
httpd: insecure handling of LD_LIBRARY_PATH in envvars2012-03-02
Debian
CVE-2012-0883: apache2 - envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-l...2012
Apache
Apache httpd: CVE-2012-0883

💬Community

1
Bugzilla
CVE-2012-0883 httpd: insecure handling of LD_LIBRARY_PATH in envvars2012-04-17
CVE-2012-0883 — Apache Http Server vulnerability | cvebase