INFORMATION

Name : CVE-2009-1195 First Publication : 2009-05-28
Severity : Medium Last Modification : 2010-08-21

SCORING CVSS v2

Cvss Base Score : 4.9 Attack Range : Local
Cvss Impact Score : 6.9 Attack Complexity : Low
Cvss Expoit Score : 3.9 Authentification : None Required

Calculate full CVSS 2.0 Vectors scores

DETAIL

The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.



CWE COMMON WEAKNESS ENUMERATION

OVALID

oval:org.mitre.oval:def:8704, Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulnerability
oval:org.mitre.oval:def:11094, The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +

oval:org.mitre.oval:def:8550, Apache HTTP Server 2.2.x is installed on the system
oval:org.mitre.oval:def:11414, The operating system installed on the system is Red Hat Enterprise Linux 5

CPE COMMON PLATFORM ENUMERATION

OPEN SOURCE VULNERABILTY DATABASE (OSVDB)

54733 : Apache HTTP Server AllowOverride Directive .htaccess Options Bypass.


SECONDARY(S) SOURCE(S)


Source : APPLE
Url : http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html

Source : BID
Url : http://www.securityfocus.com/bid/35115

Source : BUGTRAQ
Url : http://www.securityfocus.com/archive/1/archive/1/507852/100/0/threaded
Url : http://www.securityfocus.com/archive/1/archive/1/507857/100/0/threaded

Source : CONFIRM
Url : http://support.apple.com/kb/HT3937
Url : http://svn.apache.org/viewvc?view=rev&revision=772997
Url : http://wiki.rpath.com/Advisories:rPSA-2009-0142
Url : https://bugzilla.redhat.com/show_bug.cgi?id=489436

Source : DEBIAN
Url : http://www.debian.org/security/2009/dsa-1816

Source : FEDORA
Url : https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01363.html

Source : GENTOO
Url : http://security.gentoo.org/glsa/glsa-200907-04.xml

Source : MANDRIVA
Url : http://www.mandriva.com/security/advisories?name=MDVSA-2009:124

Source : MLIST
Url : http://marc.info/?l=apache-httpd-dev&m=124048996106302&w=2

Source : OSVDB
Url : http://osvdb.org/54733

Source : REDHAT
Url : http://www.redhat.com/support/errata/RHSA-2009-1075.html
Url : http://www.redhat.com/support/errata/RHSA-2009-1156.html

Source : SECTRACK
Url : http://www.securitytracker.com/id?1022296

Source : SECUNIA
Url : http://secunia.com/advisories/35261
Url : http://secunia.com/advisories/35264
Url : http://secunia.com/advisories/35395
Url : http://secunia.com/advisories/35453
Url : http://secunia.com/advisories/35721
Url : http://secunia.com/advisories/37152

Source : SUSE
Url : http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00006.html

Source : UBUNTU
Url : http://www.ubuntu.com/usn/usn-787-1

Source : VUPEN
Url : http://www.vupen.com/english/advisories/2009/1444
Url : http://www.vupen.com/english/advisories/2009/3184

Source : XF
Url : http://xforce.iss.net/xforce/xfdb/50808