The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by setuid when run on certain Linux kernels, which allows local users to gain privileges via vectors related to the number of running processes.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade mod_wsgi | Dec 1, 2016 | May 27, 2014 |
| Debian | — | Upgrade mod-wsgi | Jul 30, 2024 | May 27, 2014 |
| Gentoo Linux | — | Upgrade www-apache/mod_wsgi. | Oct 30, 2017 | May 27, 2014 |
| Oracle_linux | — | Upgrade mod_wsgi | Oct 16, 2024 | May 27, 2014 |
| Suse | — | Upgrade python-Sphinx-docUpgrade python-Werkzeug-docUpgrade apache-rpm-macrosUpgrade apache2-mod_wsgi-python3Upgrade python-pygmentsUpgrade python-FlaskUpgrade apache2-mod_wsgiUpgrade python-Flask-docUpgrade python-WerkzeugUpgrade python-SphinxUpgrade python-noseUpgrade python-itsdangerous | Dec 18, 2015 | May 27, 2014 |
| Ubuntu | — | Upgrade libapache2-mod-wsgi-py3Upgrade libapache2-mod-wsgi | Nov 8, 2024 | May 27, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub