CVE-2011-1176
Summary
| CVE | CVE-2011-1176 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-03-29 18:55:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Http Server | All | All | All | All |
| Operating System | Debian | Debian Linux | 5.0 | All | All | All |
| Operating System | Debian | Debian Linux | 6.0 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Application | Mpm-itk Project | Mpm-itk | 2.2.11-01 | All | All | All |
| Application | Mpm-itk Project | Mpm-itk | 2.2.11-02 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Support / Security / Advisories / / MDVSA-2011:057 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| oss-security - Re: CVE request: MPM-ITK module for Apache HTTPD | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Mailing List, Third Party Advisory |
| Apache MPM-ITK Module Security Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Debian -- Security Information -- DSA-2202-1 apache2 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| oss-security - CVE request: MPM-ITK module for Apache HTTPD | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Mailing List, Third Party Advisory |
| #618857 - apache2-mpm-itk: if you do not assign a user ID, the default one from Apache is _NOT_ used. - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | Issue Tracking, Patch, Third Party Advisory |
| [mpm-itk] CVE 2011-1176: Sometimes runs as root instead of the default Apache user | af854a3a-2127-422b-91ae-364da2661108 | lists.err.no | Patch, Third Party Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| [mpm-itk] mpm-itk version 2.2.17-01 released | af854a3a-2127-422b-91ae-364da2661108 | lists.err.no | Release Notes, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.