Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Ubuntu 14.04 LTS USN-2222-1 Moderate: mod_wsgi Privilege Escalation Threat

ubuntu
Calendar Grey May 26, 2014
Scroller Ubuntu
Security vulnerabilities in mod_wsgi affecting Ubuntu 14.04, 13.10, and 12.04 could lead to DoS attacks and unsafe memory issues. Patches are available.
mod_wsgi could be made to run programs as an administrator if it executes a specially crafted file.

Summary

mod_wsgi could be made to run programs as an administrator if it executes

a specially crafted file.

mod_wsgi could be made to expose sensitive information over the network.

Software Description:

- mod-wsgi: Python WSGI adapter module for Apache

Details:

Róbert Kisteleki discovered mod_wsgi incorrectly checked setuid return

values. A malicious application could use this issue to cause a local

privilege escalation when using daemon mode. (CVE-2014-0240)

Buck Golemon discovered that mod_wsgi used memory that had been freed.

A remote attacker could use this issue to read process memory via the

Content-Type response header. This issue only affected Ubuntu 12.04 LTS.

(CVE-2014-0242)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
  libapache2-mod-wsgi             3.4-4ubuntu2.1.14.04.1
  libapache2-mod-wsgi-py3         3.4-4ubuntu2.1.14.04.1

Ubuntu 13.10:
  libapache2-mod-wsgi             3.4-4ubuntu2.1.13.10.1
  libapache2-mod-wsgi-py3         3.4-4ubuntu2.1.13.10.1

Ubuntu 12.04 LTS:
  libapache2-mod-wsgi             3.3-4ubuntu0.1
  libapache2-mod-wsgi-py3         3.3-4ubuntu0.1

After a standard system update you need to restart apache2 to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2222-1

CVE-2014-0240, CVE-2014-0242

May 26, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.