CVE-2012-0883
Publication date 18 April 2012
Last updated 24 July 2024
Ubuntu priority
envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.
From the Ubuntu Security Team
jdstrand> Debian/Ubuntu packages contain 038_no_LD_LIBRARY_PATH (see http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=276670 for more information)
Status
Package | Ubuntu Release | Status |
---|---|---|
apache2 | ||
Patch details
Package | Patch details |
---|---|
apache2 |