ECHO-ad54-7743-1269

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-ad54-7743-1269.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-ad54-7743-1269
Upstream
Withdrawn
2026-07-13T15:45:01Z
Published
2026-05-28T15:40:55Z
Modified
2026-07-13T16:30:03Z
Summary
suexec in Apache HTTP Server 2.2.3 does not verify user/group ID combinations, which "might allow local users to leverage other vulnerabilities". The vendor disputes the issue because the attack "rely on an insecure server configuration" in which the unprivileged server user already has write access to the document root and can run arbitrary code; the suexec security model is not intended to protect against privilege escalation in such a configuration. NVD lists only 2.2.3 as affected (shipped version is 2.4.68). Debian: unimportant. https://security-tracker.debian.org/tracker/CVE-2007-1743
Details
References

Affected packages

Echo / apache2

Package

Name
apache2
Purl
pkg:deb/echo/apache2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.4.68-1~deb13u1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-ad54-7743-1269.json"