Vulnerability Database

290,020

Total vulnerabilities in the database

CVE-2012-0883

envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.

  • Published: Apr 18, 2012
  • Updated: Apr 13, 2023
  • CVE: CVE-2012-0883
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 6.9
  • AV:L/AC:M/Au:N/C:C/I:C/A:C

No CWE or OWASP classifications available.

Software From Fixed in
apache / http_server 2.4.1 2.4.1.x
apache / http_server 2.2.0 2.2.23
opensuse / opensuse 11.4 11.4.x
opensuse / opensuse 12.1 12.1.x