V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2014-0240
DEB
Medium

The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by setuid when run on…

CVSS
6.9
Medium
EPSS
0.00
p32
Published
2014-01-01
Updated
2014-01-01
Description

The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by setuid when run on certain Linux kernels, which allows local users to gain privileges via vectors related to the number of running processes.

Tags · CWE
LPE
CWE-264
CWE-271
Affected products
Mod_wsgi ≤ 3.4Mod_wsgi
CVSS vector
AV:L/AC:M/Au:N/C:C/I:C/A:C
Timeline
2014-01-01
Published
2014-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: C
Complete
Integrity Impact
I: C
Complete
Availability Impact
A: C
Complete
Exploit indicators
EPSS
0.004 · p32
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
mod-wsgiTracked
mod-wsgiTracked
mod_wsgiTracked
mod_wsgiTracked
python27-mod_wsgiTracked
python27-mod_wsgiTracked
python27-mod_wsgiTracked
python27-mod_wsgiTracked
python33-mod_wsgiTracked
python33-mod_wsgiTracked
python33-mod_wsgiTracked
python33-mod_wsgiTracked
mod_wsgi*Tracked
Source databases
DEB
CVE
RED
UBU