CVE-2019-0211: Apache HTTP Server Privilege Escalation Vulnerability
Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard.
Other sources
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.62-1~deb11u1Fixed in 2.4.67-1~deb11u3Fixed in 2.4.68-1~deb12u1Fixed in 2.4.67-1~deb12u3Fixed in 2.4.68-1~deb13u1Fixed in 2.4.67-1~deb13u3Fixed in 2.4.68-1 - Upgrade
Upgrade
Apache HTTP Serverto a version that resolves this vulnerability.Fixed in 2.4.38 - Compensating control
Non-Unix systems are not affected.
Event History
Frequently Asked Questions
What is CVE-2019-0211?
CVE-2019-0211 is a vulnerability in Apache HTTP Server that allows code execution with escalated privileges.
Which versions of Apache HTTP Server are affected?
Apache HTTP Server versions 2.4.17 to 2.4.38 are affected.
What is the severity of CVE-2019-0211?
CVE-2019-0211 has a severity rating of high.
How can I fix CVE-2019-0211?
Update Apache HTTP Server to version 2.4.39 or later to fix the vulnerability.
Where can I find more information about CVE-2019-0211?
You can find more information about CVE-2019-0211 on the Apache HTTP Server security page.