CVE-2014-0240
Summary
| CVE | CVE-2014-0240 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-05-27 14:55:12 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by setuid when run on certain Linux kernels, which allows local users to gain privileges via vectors related to the number of running processes. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
HighAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:H/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Modwsgi | Mod Wsgi | 1.0 | All | All | All |
| Application | Modwsgi | Mod Wsgi | 1.1 | All | All | All |
| Application | Modwsgi | Mod Wsgi | 1.2 | All | All | All |
| Application | Modwsgi | Mod Wsgi | 1.3 | All | All | All |
| Application | Modwsgi | Mod Wsgi | 1.4 | All | All | All |
| Application | Modwsgi | Mod Wsgi | 1.5 | All | All | All |
| Application | Modwsgi | Mod Wsgi | 1.6 | All | All | All |
| Application | Modwsgi | Mod Wsgi | 2.0 | All | All | All |
| Application | Modwsgi | Mod Wsgi | 2.1 | All | All | All |
| Application | Modwsgi | Mod Wsgi | 2.2 | All | All | All |
| Application | Modwsgi | Mod Wsgi | 2.3 | All | All | All |
| Application | Modwsgi | Mod Wsgi | 2.4 | All | All | All |
| Application | Modwsgi | Mod Wsgi | 2.5 | All | All | All |
| Application | Modwsgi | Mod Wsgi | 2.6 | All | All | All |
| Application | Modwsgi | Mod Wsgi | 2.7 | All | All | All |
| Application | Modwsgi | Mod Wsgi | 2.8 | All | All | All |
| Application | Modwsgi | Mod Wsgi | 3.0 | All | All | All |
| Application | Modwsgi | Mod Wsgi | 3.1 | All | All | All |
| Application | Modwsgi | Mod Wsgi | 3.2 | All | All | All |
| Application | Modwsgi | Mod Wsgi | 3.3 | All | All | All |
| Application | Modwsgi | Mod Wsgi | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Graham Dumpleton: Security release for mod_wsgi (version 3.5). | af854a3a-2127-422b-91ae-364da2661108 | blog.dscpl.com.au | |
| Apache 'mod_wsgi' Module Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Security Advisory SA60094 - Red Hat update for mod_wsgi - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Version 3.5 — mod_wsgi 4.4.5 documentation | af854a3a-2127-422b-91ae-364da2661108 | modwsgi.readthedocs.org | |
| Security Advisory SA59551 - Red Hat update for python27-mod_wsgi and python33-mod_wsgi - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| oss-security - Security release for mod_wsgi (version 3.5) | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.