Security Advisory

CVE-2006-7098

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2007-03-03 19:00:00
Last updated 2024-08-07 20:50:06
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local users to gain privileges to that tty via a CGI program that calls the TIOCSTI ioctl.