Debian Apache tty privilege escalation

debian-apache-tty-privilege-escalation (32708) The risk level is classified as HighHigh Risk

Description:

Debian Linux could allow a local attacker to gain elevated privileges caused by an error in the Apache server. The Apache server does not release the controlling tty. If the Apache server is manually started and the root shell is not closed, a local attacker could send a specially-crafted CGI script to gain root privileges on the system.

Platforms Affected:

  • Apache, Debian HTTP Server 1.3.34.4
  • Debian, Debian Linux

Remedy:

Upgrade to the latest version of Debian Apache, available to users from the Debian Web site. See References.

Consequences:

Gain Privileges

References:

  • Debian Web site, Debian -- The Universal Operating System at http://www.debian.org/.
  • Full-Disclosure Mailing List, Mon Feb 26 2007 - 12:11:23 CST, Local user to root escalation in apache 1.3.34 (Debian only) at http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0579.html.
  • BID-22732: Debian Apache Root Shell Local Privilege Escalation Vulnerabilities
  • CVE-2006-7098: The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local users to gain privileges to that tty via a CGI program that calls the TIOCSTI ioctl.
  • SA24324: Debian Apache Privilege Escalation

Reported:

Feb 26, 2007

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.

For corrections or additions please email xforce@iss.net

Return to the main page