CVE-2006-7098

Debian Apache - Access Control

Title source: rule

Description

The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local users to gain privileges to that tty via a CGI program that calls the TIOCSTI ioctl.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Kristian Hermansen · clocallinux
https://www.exploit-db.com/exploits/3384

Scores

EPSS 0.0029
EPSS Percentile 52.4%

Details

CWE
CWE-264
Status published
Products (1)
debian/apache 1.3.34.4
Published Mar 03, 2007
Tracked Since Feb 18, 2026