CVE-2007-1743
suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage other vulnerabilities to create arbitrary UID/GID owned files if /proc is mounted. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root." In addition, because this is dependent on other vulnerabilities, perhaps this is resultant and should not be included in CVE.
CVSS
- Version: 2.0
- Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P
- Base score: 4.4
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.70%
- Percentile among all scored CVEs: 52
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=511
- http://marc.info/?l=apache-httpd-dev&m=117511568709063&w=2
- http://marc.info/?l=apache-httpd-dev&m=117511834512138&w=2
- http://www.securitytracker.com/id?1017904
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=511
- http://marc.info/?l=apache-httpd-dev&m=117511568709063&w=2
- http://marc.info/?l=apache-httpd-dev&m=117511834512138&w=2
- http://www.securitytracker.com/id?1017904
Raw JSON (NVD)
Show
{
"id": "CVE-2007-1743",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.4,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.4,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-04-13T17:19:00.000",
"references": [
{
"url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=511",
"source": "secalert@redhat.com"
},
{
"url": "http://marc.info/?l=apache-httpd-dev&m=117511568709063&w=2",
"source": "secalert@redhat.com"
},
{
"url": "http://marc.info/?l=apache-httpd-dev&m=117511834512138&w=2",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securitytracker.com/id?1017904",
"source": "secalert@redhat.com"
},
{
"url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=511",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=apache-httpd-dev&m=117511568709063&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=apache-httpd-dev&m=117511834512138&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1017904",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage other vulnerabilities to create arbitrary UID/GID owned files if /proc is mounted. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because \"the attacks described rely on an insecure server configuration\" in which the user \"has write access to the document root.\" In addition, because this is dependent on other vulnerabilities, perhaps this is resultant and should not be included in CVE."
},
{
"lang": "es",
"value": "suexec en Apache HTTP Server (httpd) 2.2.3 no verifica las combinaciones de IDs de usuario y grupo sobre la linea de comandos, lo cual podría ser utilizado por un usuario local para acoplar otras vulnerabilidades en la creación de sus propios ficheros UID/GID de forma aleatoria si /proc está montado. NOTA: el investigador, que es creible, indica que el vendedor discutió este asunto porque \"los ataques descritos dependen de la condiguración del servidor no segura\" en el que el usuario \"tiene permisos de escritura sobre el documento root\". Además, dado que esto es dependiente deotras vulnerabilidades, quizás esto es el resultado y debería de incluirse en el CVE."
}
],
"lastModified": "2026-06-16T22:38:13.170",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:http_server:2.2.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F519633F-AB68-495A-B85E-FD41F9F752CA"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "These attacks are reliant on an insecure configuration of the server - that the user the server runs as has write access to the document root. The suexec security model is not intented to protect against privilege escalation in such a configuration",
"lastModified": "2007-04-19T00:00:00",
"organization": "Red Hat"
}
],
"evaluatorImpact": "From the vendor:\r\n\"The attacks described rely on an insecure server configuration - that\r\nthe unprivileged user the server runs as has write access to the\r\ndocument root. The suexec tool cannot detect all possible insecure\r\nconfigurations, nor can it protect against privilege \"escalation\" in\r\nall such cases.\r\n\r\nIt is important to note that to be able to invoke suexec, the attacker\r\nmust also first gain the ability to execute arbitrary code as the\r\nunprivileged server user.\"\r\n",
"sourceIdentifier": "secalert@redhat.com"
}