CVE-2012-0883 describes a privilege escalation vulnerability in Apache HTTP Server versions before 2.4.2, specifically affecting the envvars (or envvars-std) script. This flaw allows local users to gain privileges by placing a zero-length directory name in the LD_LIBRARY_PATH, enabling the loading of a malicious shared object (DSO) during apachectl execution. With a CVSS score of 6.9, it represents a high-severity issue with local access, medium attack complexity, and complete impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion, and it is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.2.0, < 2.2.23CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
2.4.1CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.1:*:*:*:*:*:*:* | ||
11.4CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:* | ||
12.1CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.
Apr 2, 2012httpd: insecure handling of LD_LIBRARY_PATH in envvars
Mar 2, 2012Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project