{"id":"ECHO-ad54-7743-1269","summary":"suexec in Apache HTTP Server 2.2.3 does not verify user/group ID\ncombinations, which \"might allow local users to leverage other\nvulnerabilities\". The vendor disputes the issue because the attack\n\"rely on an insecure server configuration\" in which the unprivileged\nserver user already has write access to the document root and can run\narbitrary code; the suexec security model is not intended to protect\nagainst privilege escalation in such a configuration. NVD lists only\n2.2.3 as affected (shipped version is 2.4.68). Debian: unimportant.\nhttps://security-tracker.debian.org/tracker/CVE-2007-1743\n","modified":"2026-07-13T16:30:03.933391201Z","published":"2026-05-28T15:40:55.466Z","withdrawn":"2026-07-13T15:45:01.813Z","upstream":["CVE-2007-1743"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2007-1743"}],"affected":[{"package":{"name":"apache2","ecosystem":"Echo","purl":"pkg:deb/echo/apache2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.68-1~deb13u1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-ad54-7743-1269.json"}}],"schema_version":"1.9.0"}