Lucene search

K
cvelistMitreCVELIST:CVE-2006-7098
HistoryMar 03, 2007 - 7:00 p.m.

CVE-2006-7098

2007-03-0319:00:00
mitre
www.cve.org

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

0.4%

The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local users to gain privileges to that tty via a CGI program that calls the TIOCSTI ioctl.

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

0.4%

Related for CVELIST:CVE-2006-7098