Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 95440 - net-www/apache: insecure ownership on Apache 2.x config files allow execution of arbitary code
Summary: net-www/apache: insecure ownership on Apache 2.x config files allow execution...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Default Configs (show other bugs)
Hardware: All Other
: High enhancement (vote)
Assignee: Gentoo Security
URL:
Whiteboard: [noglsa] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2005-06-08 05:05 UTC by Elfyn McBratney (beu) (RETIRED)
Modified: 2005-07-23 23:23 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
Initscript for apache that actually restarts apache (a,1.21 KB, text/plain)
2005-07-14 01:52 UTC, Ole Tange
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Elfyn McBratney (beu) (RETIRED) gentoo-dev 2005-06-08 05:05:01 UTC
Some stable versions of net-www/apache-2* install configuration files (under /etc/apache2/conf) owned by apache:apache, allowing execution of arbitrary code if a user can hi-jack an app, or run a a malicious script, as the apache user (default).

No POC, can provide one if needed .. :)
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2005-06-08 06:02:15 UTC
Well, it allows to execute arbitrary code as apache. So if you manage to get
apache rights you can execute arbitrary code as apache...

So it's not a hole in itself. It's just a bad mitigating factor, if someone
achieves apache rights on a system it easily controls the whole Apache conf.

Should be fixed, setting to "Default configs".
Comment 2 Ole Tange 2005-07-14 01:52:55 UTC
Created attachment 63372 [details]
Initscript for apache that actually restarts apache
Comment 3 Ole Tange 2005-07-14 01:55:23 UTC
Oops. Wrong bugid. Please ignore the attachment.
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-07-23 04:29:54 UTC
Apache any news on this one? 
Comment 5 Michael Stewart (vericgar) (RETIRED) gentoo-dev 2005-07-23 23:12:21 UTC
This was fixed in 2.0.54-r7, from the ChangeLog:

*apache-2.0.54-r7 (07 Jun 2005)

  07 Jun 2005; Michael Stewart <vericgar@gentoo.org> +apache-2.0.54-r7.ebuild:
  Fix installation of configuration so that it's now owned by root instead of
  apache

As there has been other security problems fixed in later revisions (see bug
98358) all arches should have the fix marked stable already.
Comment 6 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-07-23 23:23:40 UTC
Thx Michael.