CVE-2012-0883

Description

envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.

Risk Information

Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
0.197

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.4.2Windows
Update Apache to version 2.2.22Windows
Multiple vulnerabilities are fixed in Apache 2.2.2Windows
Multiple vulnerabilities are fixed in OS X Mountain Lion Update v10.8.5 (Combo)Mac
Multiple vulnerabilities are fixed in OS X Mountain Lion Update v10.8.5Mac
Update Apache to version 2.4.2 (For Linux)Linux
Update Apache to version 2.2.22 (For Linux)Linux
CVE-2012-0883NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-600057OS X Mountain Lion Update v10.8.5 (Combo)
PATCH-600058OS X Mountain Lion Update v10.8.5

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234