CVE-2012-0883: Apache HTTP Server

Medium severity, CVSS 6.9. EPSS: 0.9% chance of exploitation in the next 30 days.

envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.

Affected products

  • Apache HTTP Server: from 2.2.0, before 2.2.23 (fixed in 2.2.23); version 2.4.1 only
  • Opensuse Opensuse: version 11.4 only; version 12.1 only

Published 2012-04-18. Last modified 2026-06-16.