suexec in Apache HTTP Server 2.2.3 does not verify user/group ID
combinations, which "might allow local users to leverage other
vulnerabilities". The vendor disputes the issue because the attack
"rely on an insecure server configuration" in which the unprivileged
server user already has write access to the document root and can run
arbitrary code; the suexec security model is not intended to protect
against privilege escalation in such a configuration. NVD lists only
2.2.3 as affected (shipped version is 2.4.68). Debian: unimportant.
https://security-tracker.debian.org/tracker/CVE-2007-1743