CVE-2012-0883
Published: 18 April 2012
envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.
From the Ubuntu Security Team
jdstrand> Debian/Ubuntu packages contain 038_no_LD_LIBRARY_PATH (see http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=276670 for more information)
Priority
Status
Package | Release | Status |
---|---|---|
apache2 Launchpad, Ubuntu, Debian |
hardy |
Not vulnerable
|
lucid |
Not vulnerable
|
|
maverick |
Not vulnerable
|
|
natty |
Not vulnerable
|
|
oneiric |
Not vulnerable
|
|
upstream |
Released
(2.4.2)
|
|
Patches: upstream: http://mail-archives.apache.org/mod_mbox/httpd-cvs/201203.mbox/%3C20120308161052.6AF9B23888EA@eris.apache.org%3E |