The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Mar 29, 2011 |
| Suse | — | Upgrade apache2Upgrade apache2-example-pagesUpgrade apache2-preforkUpgrade apache2-manualUpgrade apache2-develUpgrade apache2-workerUpgrade apache2-docUpgrade apache2-eventUpgrade apache2-utils | Aug 9, 2024 | Jun 28, 2013 |
| Ubuntu | — | Upgrade apache2.2-binUpgrade apache2.2-commonUpgrade apache2-mpm-itk | Nov 8, 2024 | Mar 29, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub