CVE-2007-1743

NameCVE-2007-1743
Descriptionsuexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage other vulnerabilities to create arbitrary UID/GID owned files if /proc is mounted. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root." In addition, because this is dependent on other vulnerabilities, perhaps this is resultant and should not be included in CVE.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apache2 (PTS)buster2.4.38-3+deb10u8vulnerable
buster (security)2.4.38-3+deb10u10vulnerable
bullseye2.4.56-1~deb11u2vulnerable
bullseye (security)2.4.59-1~deb11u1vulnerable
bookworm2.4.57-2vulnerable
bookworm (security)2.4.59-1~deb12u1vulnerable
trixie2.4.58-1vulnerable
sid2.4.59-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
apache2source(unstable)(unfixed)unimportant

Search for package or bug name: Reporting problems