6.9
CVSSv2

CVE-2014-8583

Published: 16/12/2014 Updated: 01/07/2017
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

mod_wsgi prior to 4.2.4 for Apache, when creating a daemon process group, does not properly handle when group privileges cannot be dropped, which might allow malicious users to gain privileges via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

modwsgi mod wsgi

Vendor Advisories

mod_wsgi could be made to run programs with incorrect privileges ...
Failure to handle errors when attempting to drop group privileges:mod_wsgi before 424 for Apache, when creating a daemon process group, does not properly handle when group privileges cannot be dropped, which might allow attackers to gain privileges via unspecified vectors (CVE-2014-8583) ...
Failure to handle errors when attempting to drop group privilegesmod_wsgi before 424 for Apache, when creating a daemon process group, does not properly handle when group privileges cannot be dropped, which might allow attackers to gain privileges via unspecified vectors (CVE-2014-8583) ...
mod_wsgi before 424 for Apache, when creating a daemon process group, does not properly handle when group privileges cannot be dropped, which might allow attackers to gain privileges via unspecified vectors ...