Total vulnerabilities in the database
envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.
Software | From | Fixed in |
---|---|---|
apache / http_server | 2.4.1 | 2.4.1.x |
apache / http_server | 2.2.0 | 2.2.23 |
opensuse / opensuse | 11.4 | 11.4.x |
opensuse / opensuse | 12.1 | 12.1.x |