CVE-2006-7098

Debian apache - Local Privilege Escalation via TIOCSTI ioctl in CGI Program

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-7098. PoCs published by Kristian Hermansen.

AI-analyzed exploit summary This exploit leverages a vulnerability in Apache 1.3.33/1.3.34 on Debian/Ubuntu systems to inject commands into an open TTY owned by the root user. It uses the TIOCSTI ioctl to push commands into the terminal input buffer, resulting in arbitrary command execution.

Description

The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local users to gain privileges to that tty via a CGI program that calls the TIOCSTI ioctl.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Kristian Hermansen · clocallinux
https://www.exploit-db.com/exploits/3384

This exploit leverages a vulnerability in Apache 1.3.33/1.3.34 on Debian/Ubuntu systems to inject commands into an open TTY owned by the root user. It uses the TIOCSTI ioctl to push commands into the terminal input buffer, resulting in arbitrary command execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Apache 1.3.33/1.3.34 on Debian/Ubuntu
No auth needed
Prerequisites: CGI execution privileges · Apache service started manually by root via shell
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0579.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/22732
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/32708
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/33816
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/24324
Issue Tracking x_refsource_confirm
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=357561

Scores

EPSS 0.0056
EPSS Percentile 42.1%

Details

CWE
CWE-264
Status published
Products (1)
debian/apache 1.3.34.4
Published Mar 03, 2007
Tracked Since Feb 18, 2026