← Back

CVE-2014-0240

nvd nist
Published: May 27, 2014Modified: May 6, 2026

JSON object

Loading...
6.2
Vector
AV:L/AC:H/Au:N/C:C/I:C/A:C
Exploitability: 1.9 / Impact: 10.0
Source: NVD

Description

The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by setuid when run on certain Linux kernels, which allows local users to gain privileges via vectors related to the number of running processes.

Affected (21)

Products: Modwsgi: Mod Wsgi
1 product
Mod Wsgi
Configuration A
21 vulnerable
Vulnerable SoftwareAffected Versions
Modwsgi
Up to 3.4
Version 1.0
Version 1.1
Version 1.2
Version 1.3
Version 1.4
Version 1.5
Version 1.6
Version 2.0
Version 2.1
Version 2.2
Version 2.3
Version 2.4
Version 2.5
Version 2.6
Version 2.7
Version 2.8
Version 3.0
Version 3.1
Version 3.2
Version 3.3

Related CWEs

References (14)

Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.