Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2012-0883

24
FAUCET Score

CVE-2012-0883 describes a privilege escalation vulnerability in Apache HTTP Server versions before 2.4.2, specifically affecting the envvars (or envvars-std) script. This flaw allows local users to gain privileges by placing a zero-length directory name in the LD_LIBRARY_PATH, enabling the loading of a malicious shared object (DSO) during apachectl execution. With a CVSS score of 6.9, it represents a high-severity issue with local access, medium attack complexity, and complete impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion, and it is not listed on the CISA KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.2.0, < 2.2.23CPE matchmatch criteria
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
2.4.1CPE matchmatch criteria
cpe:2.3:a:apache:http_server:2.4.1:*:*:*:*:*:*:*
11.4CPE matchmatch criteria
cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
12.1CPE matchmatch criteria
cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.9MEDIUM

AV:L/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
3.4
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.95%
Probability of exploitation in next 30 days
EPSS Percentile
57.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0095 is in the 90th percentile among its peer group of 1,595 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

apachepatch availablevia llm_extracted
Fixed in: 2.4
microsoftpatch availablevia msrc
Product: azl3 httpd 2.4.62-1 on Azure Linux 3.0
microsoftpatch availablevia msrc
Product: 19236-17084Fixed in: httpd-2.4.2
microsoftpatch availablevia msrc
Product: azl3 httpd httpd-2.4.2 on Azure Linux 3.0Fixed in: httpd-2.4.2
microsoftpatch availablevia msrc
Product: 17686-17084
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6.0
View patch
redhatend of lifevia redhat_api
Product: Red Hat JBoss Enterprise Web Server 1Fixed in: httpd

Vendor Advisories (5)

apachellm-apache-f398f8ed28802aa3LOW

Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project

Mar 2, 2026
apachellm-apache-a7a91ec4c0e9421dHIGH

Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project

Dec 10, 2025
microsoft2012-Apr/CVE-2012-0883Moderate

envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.

Apr 2, 2012
redhatCVE-2012-0883Low

httpd: insecure handling of LD_LIBRARY_PATH in envvars

Mar 2, 2012
apachellm-apache-684e4d0003611bd4LOW

Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project

References

article.gmane.org / gmane.comp.apache.devel/48158
Broken Link
lists.apple.com / archives/security-announce/2013/Sep/msg00002.html
Broken LinkMailing List
lists.opensuse.org / opensuse-updates/2013-02/msg00009.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-updates/2013-02/msg00012.html
Mailing ListThird Party Advisory
marc.info
Issue TrackingMailing ListThird Party Advisory
secunia.com / advisories/48849
Not Applicable
exchange.xforce.ibmcloud.com / vulnerabilities/74901
Third Party AdvisoryVDB Entry
h20564.www2.hp.com / portal/site/hpsc/public/kb/docDisplay
Broken Link
httpd.apache.org / security/vulnerabilities_24.html
Vendor Advisory
lists.apache.org / thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r05b5357d1f6bd106f41541ee7d87aafe3f5ea4dc3e9bde5ce09baff8%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r1d201e3da31a2c8aa870c8314623caef7debd74a13d0f25205e26f15%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r9b4b963760a3cb5a4a70c902f325c6c0337fe51d5b8570416f8f8729%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E
support.apple.com / kb/HT5880
Broken LinkThird Party Advisory
svn.apache.org / viewvc
PatchVendor Advisory
apachelounge.com / Changelog-2.4.html
Release NotesThird Party Advisory
apache.org / dist/httpd/Announcement2.4.html
Vendor Advisory
securityfocus.com / bid/53046
Third Party AdvisoryVDB Entry
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
xerox.com / download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf
Third Party Advisory