CVE-2012-0883

Priority
Negligible
Description
envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a
zero-length directory name in the LD_LIBRARY_PATH, which allows local users
to gain privileges via a Trojan horse DSO in the current working directory
during execution of apachectl.
Ubuntu-Description
jdstrand> Debian/Ubuntu packages contain 038_no_LD_LIBRARY_PATH (see
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=276670 for more information)
References
Package
Upstream:released (2.4.2)
Patches:
Upstream:http://mail-archives.apache.org/mod_mbox/httpd-cvs/201203.mbox/%3C20120308161052.6AF9B23888EA@eris.apache.org%3E
More Information

Updated: 2017-12-14 19:56:33 UTC (commit 13907)