Vulnerabilities > CVE-2011-1176
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 | |
Application | 1 | |
OS | 3 |
Nessus
NASL family Ubuntu Local Security Checks NASL id UBUNTU_USN-1259-1.NASL description It was discovered that the mod_proxy module in Apache did not properly interact with the RewriteRule and ProxyPassMatch pattern matches in the configuration of a reverse proxy. This could allow remote attackers to contact internal webservers behind the proxy that were not intended for external exposure. (CVE-2011-3368) Stefano Nichele discovered that the mod_proxy_ajp module in Apache when used with mod_proxy_balancer in certain configurations could allow remote attackers to cause a denial of service via a malformed HTTP request. (CVE-2011-3348) Samuel Montosa discovered that the ITK Multi-Processing Module for Apache did not properly handle certain configuration sections that specify NiceValue but not AssignUserID, preventing Apache from dropping privileges correctly. This issue only affected Ubuntu 10.04 LTS, Ubuntu 10.10 and Ubuntu 11.04. (CVE-2011-1176) USN 1199-1 fixed a vulnerability in the byterange filter of Apache. The upstream patch introduced a regression in Apache when handling specific byte range requests. This update fixes the issue. A flaw was discovered in the byterange filter in Apache. A remote attacker could exploit this to cause a denial of service via resource exhaustion. Note that Tenable Network Security has extracted the preceding description block directly from the Ubuntu security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-01 modified 2020-06-02 plugin id 56778 published 2011-11-11 reporter Ubuntu Security Notice (C) 2011-2019 Canonical, Inc. / NASL script (C) 2011-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/56778 title Ubuntu 8.04 LTS / 10.04 LTS / 10.10 / 11.04 / 11.10 : apache2, apache2-mpm-itk vulnerabilities (USN-1259-1) NASL family Mandriva Local Security Checks NASL id MANDRIVA_MDVSA-2011-057.NASL description The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module (apache-mpm-itk) for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process (CVE-2011-1176). Packages for 2009.0 are provided as of the Extended Maintenance Program. Please visit this link to learn more: http://store.mandriva.com/product_info.php?cPath=149 products_id=490 The updated packages uses the latest upstream ITK patch for apache that is unaffected by this issue. last seen 2020-06-01 modified 2020-06-02 plugin id 53244 published 2011-04-01 reporter This script is Copyright (C) 2011-2019 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/53244 title Mandriva Linux Security Advisory : apache (MDVSA-2011:057) NASL family Debian Local Security Checks NASL id DEBIAN_DSA-2202.NASL description MPM_ITK is an alternative Multi-Processing Module for Apache HTTPD that is included in Debian last seen 2020-03-17 modified 2011-03-24 plugin id 52949 published 2011-03-24 reporter This script is Copyright (C) 2011-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/52949 title Debian DSA-2202-1 : apache2 - failure to drop root privileges
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=618857
- http://lists.err.no/pipermail/mpm-itk/2011-March/000393.html
- http://lists.err.no/pipermail/mpm-itk/2011-March/000394.html
- http://openwall.com/lists/oss-security/2011/03/20/1
- http://openwall.com/lists/oss-security/2011/03/21/13
- http://www.debian.org/security/2011/dsa-2202
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:057
- http://www.securityfocus.com/bid/46953
- http://www.vupen.com/english/advisories/2011/0748
- http://www.vupen.com/english/advisories/2011/0749
- http://www.vupen.com/english/advisories/2011/0824
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66248