CVE-2006-7098: Medium severity Debian Apache vulnerability
Published Mar 3, 2007
·Updated
The Debian GNU/Linux 033-FNOSETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local users to gain privileges to that tty via a CGI program that calls the TIOCSTI ioctl.
Affected Software
1 affected component
Debian Apache=1.3.34.4
Event History
Mar 3, 2007
CVE Published
07:19 PM
Mar 4, 2007
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-7098?
CVE-2006-7098 is considered a local privilege escalation vulnerability.
2
How do I fix CVE-2006-7098?
Fix CVE-2006-7098 by applying the latest patches or upgrading to a non-affected version of Apache.
3
Who is affected by CVE-2006-7098?
CVE-2006-7098 affects users running Debian GNU/Linux with Apache HTTP Server version 1.3.34-4.
4
What type of vulnerability is CVE-2006-7098?
CVE-2006-7098 is a vulnerability related to improper disassociation of a controlling tty in Apache.
5
Can CVE-2006-7098 be exploited remotely?
CVE-2006-7098 requires local access, thus it cannot be exploited remotely.