---
title: "CVE-2007-1742\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2007-1742?format=md
keywords: index, follow
---

# CVE-2007-1742

Publication date 13 April 2007

Last updated 4 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for
verifying whether the current directory is within the document root, which
might allow local users to perform unauthorized operations on incorrect
directories, as demonstrated using "html\_backup" and "htmleditor" under an
"html" directory. NOTE: the researcher, who is reliable, claims that the
vendor disputes the issue because "the attacks described rely on an
insecure server configuration" in which the user "has write access to the
document root."

[Read the notes from the security team](https://ubuntu.com/security/CVE-2007-1742?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| apache2 | 7.04 feisty | Ignored |
| 6.10 edgy | Ignored |
| 6.06 LTS dapper | Ignored |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [kees](https://launchpad.net/~kees)

negligible addition checks for suexec

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1742)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2007-1742)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2007-1742)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2007-1742)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2007-1742>
