ECHO-4685-aa81-91fd

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-4685-aa81-91fd.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-4685-aa81-91fd
Upstream
Withdrawn
2026-07-13T15:45:01Z
Published
2026-05-28T15:34:43Z
Modified
2026-07-13T16:30:03Z
Summary
Reported against the mod_php module for Apache 2.0.x, allowing local users with write access to PHP scripts to signal the server process group and reuse its file descriptors. The PHP developers disputed the report ("The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP"), and Red Hat states it "is not a vulnerability" since mod_php runs with the privileges of the httpd child by design. NVD carries the "disputed" tag. mod_php is not shipped by the apache2 source package and is not used in these images. https://security-tracker.debian.org/tracker/CVE-2003-1307
Details
References

Affected packages

Echo / apache2

Package

Name
apache2
Purl
pkg:deb/echo/apache2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.4.68-1~deb13u1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-4685-aa81-91fd.json"