envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.
https://httpd.apache.org/security/vulnerabilities_24.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/74901
http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf
http://www.securityfocus.com/bid/53046
http://www.apachelounge.com/Changelog-2.4.html
http://www.apache.org/dist/httpd/Announcement2.4.html
http://svn.apache.org/viewvc?view=revision&revision=1296428
http://secunia.com/advisories/48849
http://marc.info/?l=bugtraq&m=134012830914727&w=2
http://lists.opensuse.org/opensuse-updates/2013-02/msg00012.html
http://lists.opensuse.org/opensuse-updates/2013-02/msg00009.html