Lucene search

K
ubuntucveUbuntu.comUB:CVE-2006-7098
HistoryMar 03, 2007 - 12:00 a.m.

CVE-2006-7098

2007-03-0300:00:00
ubuntu.com
ubuntu.com
10

6.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:S/C:C/I:C/A:C

0.0004 Low

EPSS

Percentile

0.4%

The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server
1.3.34-4 does not properly disassociate httpd from a controlling tty when
httpd is started interactively, which allows local users to gain privileges
to that tty via a CGI program that calls the TIOCSTI ioctl.

6.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:S/C:C/I:C/A:C

0.0004 Low

EPSS

Percentile

0.4%

Related for UB:CVE-2006-7098