Apache HTTP Server 'LD_LIBRARY_PATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
BID:53046
Info
Apache HTTP Server 'LD_LIBRARY_PATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 53046 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-0883 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 17 2012 12:00AM |
| Updated: | Sep 21 2013 12:11AM |
| Credit: | Stefan Fritsch |
| Vulnerable: |
Xerox FreeFlow Print Server (FFPS) 73.C0.41 Xerox FreeFlow Print Server (FFPS) 73.B3.61 Sun Solaris 11 Sun Solaris 10 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 HP System Management Homepage 7.0 HP HP-UX B.11.31 HP HP-UX B.11.23 Gentoo Linux Apple Mac Os X Server 10.6.8 Apache Software Foundation Apache 2.3.6 Apache Software Foundation Apache 2.3.5 Apache Software Foundation Apache 2.3.4 Apache Software Foundation Apache 2.3.2 Apache Software Foundation Apache 2.3.1 Apache Software Foundation Apache 2.3 Apache Software Foundation Apache 2.2.15 Apache Software Foundation Apache 2.2.14 Apache Software Foundation Apache 2.2.13 Apache Software Foundation Apache 2.2.12 Apache Software Foundation Apache 2.2.11 Apache Software Foundation Apache 2.2.10 Apache Software Foundation Apache 2.2.9 Apache Software Foundation Apache 2.2.8 Apache Software Foundation Apache 2.2.6 Apache Software Foundation Apache 2.2.5 Apache Software Foundation Apache 2.2.4 Apache Software Foundation Apache 2.2.3 Apache Software Foundation Apache 2.2.2 Apache Software Foundation Apache 2.2 Apache Software Foundation Apache 2.1.9 Apache Software Foundation Apache 2.1.8 Apache Software Foundation Apache 2.1.7 Apache Software Foundation Apache 2.1.6 Apache Software Foundation Apache 2.1.5 Apache Software Foundation Apache 2.1.4 Apache Software Foundation Apache 2.1.3 Apache Software Foundation Apache 2.1.2 Apache Software Foundation Apache 2.1.1 Apache Software Foundation Apache 2.1 Apache Software Foundation Apache 2.0.63 Apache Software Foundation Apache 2.0.61 Apache Software Foundation Apache 2.0.60 Apache Software Foundation Apache 2.0.59 Apache Software Foundation Apache 2.0.58 Apache Software Foundation Apache 2.0.57 Apache Software Foundation Apache 2.0.56 -dev Apache Software Foundation Apache 2.0.56 Apache Software Foundation Apache 2.0.55 Apache Software Foundation Apache 2.0.54 Apache Software Foundation Apache 2.0.53 Apache Software Foundation Apache 2.0.52 Apache Software Foundation Apache 2.0.51 Apache Software Foundation Apache 2.0.50 Apache Software Foundation Apache 2.0.49 Apache Software Foundation Apache 2.0.48 Apache Software Foundation Apache 2.0.47 Apache Software Foundation Apache 2.0.46 Apache Software Foundation Apache 2.0.45 Apache Software Foundation Apache 2.0.44 Apache Software Foundation Apache 2.0.43 Apache Software Foundation Apache 2.0.42 Apache Software Foundation Apache 2.0.41 Apache Software Foundation Apache 2.0.40 Apache Software Foundation Apache 2.0.39 Apache Software Foundation Apache 2.0.38 Apache Software Foundation Apache 2.0.37 Apache Software Foundation Apache 2.0.36 Apache Software Foundation Apache 2.0.35 Apache Software Foundation Apache 2.0.34 -BETA Apache Software Foundation Apache 2.0.32 -BETA Apache Software Foundation Apache 2.0.32 Apache Software Foundation Apache 2.0.28 -BETA Apache Software Foundation Apache 2.0.28 Beta Apache Software Foundation Apache 2.0.28 Apache Software Foundation Apache 2.0.9 Apache Software Foundation Apache 2.0 a9 Apache Software Foundation Apache 2.0 Apache Software Foundation Apache 2.3.38-dev Apache Software Foundation Apache 2.3.3 Apache Software Foundation Apache 2.2.7-dev Apache Software Foundation Apache 2.2.6-dev Apache Software Foundation Apache 2.2.5-dev Apache Software Foundation Apache 2.2.22-dev Apache Software Foundation Apache 2.2.22 Apache Software Foundation Apache 2.2.21 Apache Software Foundation Apache 2.2.21 Apache Software Foundation Apache 2.2.20 Apache Software Foundation Apache 2.2.19 Apache Software Foundation Apache 2.2.18 Apache Software Foundation Apache 2.2.17 Apache Software Foundation Apache 2.2.16 Apache Software Foundation Apache 2.2.15-dev Apache Software Foundation Apache 2.2.1 Apache Software Foundation Apache 2.2 Apache Software Foundation Apache 2.0.64-dev Apache Software Foundation Apache 2.0.64 Apache Software Foundation Apache 2.0.62-dev Apache Software Foundation Apache 2.0.61-dev Apache Software Foundation Apache 2.0.60-dev |
| Not Vulnerable: |
Apache Software Foundation Apache 2.4.2 |
Discussion
Apache HTTP Server 'LD_LIBRARY_PATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
Apache HTTP Server is prone to a vulnerability that lets attackers execute arbitrary code.
A successful exploit can allow the attacker to execute arbitrary code in the context of the user running the affected application.
Apache HTTP Server is prone to a vulnerability that lets attackers execute arbitrary code.
A successful exploit can allow the attacker to execute arbitrary code in the context of the user running the affected application.
Exploit / POC
Apache HTTP Server 'LD_LIBRARY_PATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
Attackers can exploit the issue using standard commands.
Attackers can exploit the issue using standard commands.
Solution / Fix
Apache HTTP Server 'LD_LIBRARY_PATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Apache HTTP Server 'LD_LIBRARY_PATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
References:
References:
- Apache Homepage (Apache)
- Apache HTTP Server 2.4.2 Released (Apache Software Foundation)
- Changes with Apache 2.4.2 (Apache Software Foundation)