Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-7098

Опубликовано: 03 мар. 2007
Источник: nvd
CVSS2: 6.6
EPSS Низкий

Описание

The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local users to gain privileges to that tty via a CGI program that calls the TIOCSTI ioctl.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:debian:apache:1.3.34.4:*:*:*:*:*:*:*

EPSS

Процентиль: 33%
0.00126
Низкий

6.6 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
больше 18 лет назад

The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local users to gain privileges to that tty via a CGI program that calls the TIOCSTI ioctl.

debian
больше 18 лет назад

The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server ...

github
больше 3 лет назад

The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local users to gain privileges to that tty via a CGI program that calls the TIOCSTI ioctl.

EPSS

Процентиль: 33%
0.00126
Низкий

6.6 Medium

CVSS2

Дефекты

CWE-264