Release date:
Updated on:
Affected Systems:
Apache Group HTTP Server <2.4.2
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2012-0883
Apache HTTP Server is an open-source Web Server of the Apache Software Foundation. It can run in most computer operating systems. Because of its wide use of multiple platforms and security, is one of the most popular Web server software.
The envvars (envvars-std) version earlier than Apache HTTP Server 2.4.2 has a zero-length directory name in LD_LIBRARY_PATH, allows local users to obtain permissions through the trojan DSO in the current working directory during apachectl execution.
<* Source: vendor
Link: http://www.securitytracker.com/id? 1026932
Http://www.apache.org/dist/httpd/Announcement2.2.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
For this reason, Apache Group has released a Security Bulletin (Announcement2.2) and corresponding patches:
Announcement2.2: Apache HTTP Server 2.2.23 Released
Link: http://www.apache.org/dist/httpd/Announcement2.2.html