Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-66200

Опубликовано: 05 дек. 2025
Источник: ubuntu
Приоритет: medium
CVSS3: 5.4

Описание

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

РелизСтатусПримечание
devel

released

2.4.66-2ubuntu1
esm-infra-legacy/trusty

released

2.4.7-1ubuntu4.22+esm12
esm-infra-legacy/xenial

released

2.4.18-2ubuntu3.17+esm17
esm-infra/bionic

released

2.4.29-1ubuntu4.27+esm7
esm-infra/focal

released

2.4.41-4ubuntu3.23+esm3
esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

released

2.4.52-1ubuntu4.18
noble

released

2.4.58-1ubuntu8.10
plucky

ignored

end of life, was needs-triage
questing

released

2.4.64-1ubuntu3.2

Показывать по

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
redhat
8 месяцев назад

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 5.4
nvd
8 месяцев назад

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 5.4
msrc
8 месяцев назад

Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo

CVSS3: 5.4
debian
8 месяцев назад

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in ...

CVSS3: 5.4
github
8 месяцев назад

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

5.4 Medium

CVSS3