CVE-2007-1741
Estado: ModificadaMedia (6.2)—
Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
CVSS
- Versión: 2.0
- Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C
- Puntuación base: 6.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.52%
- Percentil entre todas las CVEs puntuadas: 42
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-362
Referencias
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=511
- http://marc.info/?l=apache-httpd-dev&m=117511568709063&w=2
- http://marc.info/?l=apache-httpd-dev&m=117511834512138&w=2
- http://osvdb.org/38639
- http://www.securityfocus.com/bid/23438
- http://www.securitytracker.com/id?1017904
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33584
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=511
- http://marc.info/?l=apache-httpd-dev&m=117511568709063&w=2
- http://marc.info/?l=apache-httpd-dev&m=117511834512138&w=2
- http://osvdb.org/38639
- http://www.securityfocus.com/bid/23438
- http://www.securitytracker.com/id?1017904
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33584
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-1741",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:H/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "HIGH",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": true,
"exploitabilityScore": 1.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-04-13T16:19:00.000",
"references": [
{
"url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=511",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://marc.info/?l=apache-httpd-dev&m=117511568709063&w=2",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://marc.info/?l=apache-httpd-dev&m=117511834512138&w=2",
"source": "secalert@redhat.com"
},
{
"url": "http://osvdb.org/38639",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/23438",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securitytracker.com/id?1017904",
"source": "secalert@redhat.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/33584",
"source": "secalert@redhat.com"
},
{
"url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=511",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=apache-httpd-dev&m=117511568709063&w=2",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=apache-httpd-dev&m=117511834512138&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/38639",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/23438",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1017904",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/33584",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-362"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because \"the attacks described rely on an insecure server configuration\" in which the user \"has write access to the document root.\""
},
{
"lang": "es",
"value": "Múltiples condiciones de carrera en suexec en Apache HTTP Server (httpd) versión 2.2.3, entre la comprobación de directorios y archivos, y su uso, permiten a usuarios locales alcanzar privilegios y ejecutar código arbitrario mediante el cambio del nombre de los directorios o realizando ataques de tipo symlink. NOTA: el investigador, que es confiable, afirma que el proveedor cuestiona el problema porque \"the attacks described rely on an insecure server configuration\" en la que el usuario \"has write access to the document root”."
}
],
"lastModified": "2026-06-16T22:38:12.970",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:http_server:2.2.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F519633F-AB68-495A-B85E-FD41F9F752CA"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "These attacks are reliant on an insecure configuration of the server - that the user the server runs as has write access to the document root. The suexec security model is not intented to protect against privilege escalation in such a configuration",
"lastModified": "2007-04-19T00:00:00",
"organization": "Red Hat"
}
],
"sourceIdentifier": "secalert@redhat.com"
}