{"id":"ECHO-4685-aa81-91fd","summary":"Reported against the mod_php module for Apache 2.0.x, allowing local\nusers with write access to PHP scripts to signal the server process\ngroup and reuse its file descriptors. The PHP developers disputed the\nreport (\"The opened file descriptors are opened by Apache. It is the job\nof Apache to protect them ... Not a bug in PHP\"), and Red Hat states it\n\"is not a vulnerability\" since mod_php runs with the privileges of the\nhttpd child by design. NVD carries the \"disputed\" tag. mod_php is not\nshipped by the apache2 source package and is not used in these images.\nhttps://security-tracker.debian.org/tracker/CVE-2003-1307\n","modified":"2026-07-13T16:30:03.902386826Z","published":"2026-05-28T15:34:43.602Z","withdrawn":"2026-07-13T15:45:01.813Z","upstream":["CVE-2003-1307"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2003-1307"}],"affected":[{"package":{"name":"apache2","ecosystem":"Echo","purl":"pkg:deb/echo/apache2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.68-1~deb13u1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-4685-aa81-91fd.json"}}],"schema_version":"1.9.0"}