Release date:
Updated on:
Affected Systems:
Apache Group mod_wsgi <3.5
Description:
--------------------------------------------------------------------------------
Bugtraq id: 67532
CVE (CAN) ID: CVE-2014-0240
Mod_wsgi is an Apache HTTP server module that provides WSGI compatible interfaces for hosting Web applications based on Python 2.3 +.
After the background mode is enabled in versions earlier than mod_wsgi 3.5, when running on some linux kernels, the error code returned by setuid is not correctly handled. This allows local users to run the number of processes, attackers can exploit this vulnerability to obtain elevated permissions.
<* Source: R & amp; oacute; bert Kisteleki
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://modwsgi.readthedocs.org/en/latest/release-notes/version-3.5.html
This article permanently updates the link address: