CVE-2007-1588

server.cpp in MyServer 0.8.5 calls Process::setuid before calling Process::setgid and thus does not properly drop privileges, which might allow remote attackers to execute CGI programs with unintended privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:myserver:myserver:0.8.5:*:*:*:*:*:*:*

History

21 Nov 2024, 00:28

Type Values Removed Values Added
References () http://osvdb.org/34521 - () http://osvdb.org/34521 -
References () http://sourceforge.net/mailarchive/forum.php?thread_id=31631045&forum_id=47875 - Patch () http://sourceforge.net/mailarchive/forum.php?thread_id=31631045&forum_id=47875 - Patch
References () http://www.myserverproject.net/news.php - Vendor Advisory () http://www.myserverproject.net/news.php - Vendor Advisory

Information

Published : 2007-03-21 23:19

Updated : 2024-11-21 00:28


NVD link : CVE-2007-1588

Mitre link : CVE-2007-1588

CVE.ORG link : CVE-2007-1588


JSON object : View

Products Affected

myserver

  • myserver