Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Scientific Linux: SLSA-2014:0788-1 Important mod_wsgi Security Advisory

Scientific Large Esm H446
Important: mod_wsgi security update
Date: Wed, 25 Jun 2014 17:57:53 +0000
Reply-To: scientific-linux-users@
Sender: Security Errata for Scientific Linux
 
From: Pat Riehecky 
Subject: Security ERRATA Important: mod_wsgi on SL6.x i386/srpm/x86_64
MIME-Version: 1.0

Synopsis: Important: mod_wsgi security update
Advisory ID: SLSA-2014:0788-1
Issue Date: 2014-06-25
CVE Numbers: CVE-2014-0240
 CVE-2014-0242
--

It was found that mod_wsgi did not properly drop privileges if the call to
setuid() failed. If mod_wsgi was set up to allow unprivileged users to run
WSGI applications, a local user able to run a WSGI application could
possibly use this flaw to escalate their privileges on the system.
(CVE-2014-0240)

Note: mod_wsgi is not intended to provide privilege separation for WSGI
applications. Systems relying on mod_wsgi to limit or sandbox the
privileges of mod_wsgi applications should migrate to a different solution
with proper privilege separation.

It was discovered that mod_wsgi could leak memory of a hosted web
application via the "Content-Type" header. A remote attacker could
possibly use this flaw to disclose limited portions of the web
application's memory. (CVE-2014-0242)
--

SL6
 x86_64
 mod_wsgi-3.2-6.el6_5.x86_64.rpm
 mod_wsgi-debuginfo-3.2-6.el6_5.x86_64.rpm
 i386
 mod_wsgi-3.2-6.el6_5.i686.rpm
 mod_wsgi-debuginfo-3.2-6.el6_5.i686.rpm
 srpm
 mod_wsgi-3.2-6.el6_5.src.rpm

- Scientific Linux Development Team