CVE-2011-1176

NameCVE-2011-1176
DescriptionThe configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-2202-1
Debian Bugs618857

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apache2 (PTS)jessie, jessie (lts)2.4.10-10+deb8u25fixed
stretch (security)2.4.25-3+deb9u13fixed
stretch (lts), stretch2.4.25-3+deb9u15fixed
buster2.4.38-3+deb10u8fixed
buster (security)2.4.38-3+deb10u10fixed
bullseye2.4.56-1~deb11u2fixed
bullseye (security)2.4.59-1~deb11u1fixed
bookworm2.4.57-2fixed
bookworm (security)2.4.59-1~deb12u1fixed
trixie2.4.58-1fixed
sid2.4.59-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
apache2sourcelenny(not affected)
apache2sourcesqueeze2.2.16-6+squeeze1DSA-2202-1
apache2source(unstable)2.2.17-2medium618857
apache2-mpm-itksourcelenny(not affected)
apache2-mpm-itksource(unstable)(unfixed)

Notes

[lenny] - apache2 <not-affected> (different source package in lenny: apache2-mpm-itk)
[lenny] - apache2-mpm-itk <not-affected> (bug was introduced later, in 2.2.11-01)

Search for package or bug name: Reporting problems