Apache HTTP Server CVE-2019-0211 Local Privilege Escalation Vulnerability
BID:107666
CVE-2019-211 |Info
Apache HTTP Server CVE-2019-0211 Local Privilege Escalation Vulnerability
| Bugtraq ID: | 107666 |
| Class: | Design Error |
| CVE: |
CVE-2019-0211 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 01 2019 12:00AM |
| Updated: | Jul 17 2019 06:00AM |
| Credit: | Charles Fol. |
| Vulnerable: |
Oracle Retail Xstore Point of Service 7.1 Oracle Retail Xstore Point of Service 7.0 Oracle HTTP Server 12.2.1.3.0 Oracle Enterprise Manager Ops Center 12.4 Oracle Enterprise Manager Ops Center 12.3.3 Apache Apache 2.4.38 Apache Apache 2.4.37 Apache Apache 2.4.33 Apache Apache 2.4.26 Apache Apache 2.4.25 Apache Apache 2.4.23 Apache Apache 2.4.20 Apache Apache 2.4.18 Apache Apache 2.4.17 Apache Apache 2.4.35 Apache Apache 2.4.34 Apache Apache 2.4.30 Apache Apache 2.4.29 Apache Apache 2.4.28 Apache Apache 2.4.27 |
| Not Vulnerable: |
Apache Apache 2.4.39 |
Discussion
Apache HTTP Server CVE-2019-0211 Local Privilege Escalation Vulnerability
Apache HTTP Server is prone to a local privilege-escalation vulnerability.
An attacker can exploit this issue to gain elevated privileges on the affected application.
Apache HTTP Server versions 2.4.38, 2.4.37, 2.4.35, 2.4.34, 2.4.33, 2.4.30, 2.4.29, 2.4.28, 2.4.27, 2.4.26, 2.4.25, 2.4.23, 2.4.20, 2.4.18, and 2.4.17 are vulnerable.
Apache HTTP Server is prone to a local privilege-escalation vulnerability.
An attacker can exploit this issue to gain elevated privileges on the affected application.
Apache HTTP Server versions 2.4.38, 2.4.37, 2.4.35, 2.4.34, 2.4.33, 2.4.30, 2.4.29, 2.4.28, 2.4.27, 2.4.26, 2.4.25, 2.4.23, 2.4.20, 2.4.18, and 2.4.17 are vulnerable.
Exploit / POC
Apache HTTP Server CVE-2019-0211 Local Privilege Escalation Vulnerability
An exploit is available. Please see the references for more information.
An exploit is available. Please see the references for more information.
Solution / Fix
Apache HTTP Server CVE-2019-0211 Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache HTTP Server CVE-2019-0211 Local Privilege Escalation Vulnerability
References:
References:
- CVE-2019-0211: Apache HTTP Server privilege escalation from modules' scripts (Seclists.org)
- Apache Homepage (Apache)
- CARPE (DIEM): CVE-2019-0211 Apache Root Privilege Escalation (cfreal)
- CVE-2019-0211 Apache Root Privilege Escalation (cfreal)
- Bug 1694980 (CVE-2019-0211) - CVE-2019-0211 httpd: privilege escalation from mo (Redhat)
- Apache httpd 2.4 vulnerabilities (Apache)
- CVE-2019-0211 (Redhat)
- Oracle Critical Patch Update Advisory - July 2019 (Oracle)