Vulnerability Name: | CVE-2001-0131 (CCN-5926) | ||||||||||||||||
Assigned: | 2001-01-10 | ||||||||||||||||
Published: | 2001-01-10 | ||||||||||||||||
Updated: | 2020-10-09 | ||||||||||||||||
Summary: | htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack. | ||||||||||||||||
CVSS v3 Severity: | 2.9 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 3.3 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-59 | ||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2001-0131 Source: BUGTRAQ Type: Third Party Advisory 20010110 Immunix OS Security update for lots of temp file problems Source: DEBIAN Type: Patch, Third Party Advisory DSA-021 Source: DEBIAN Type: DSA-021 apache -- insecure tempfile bug Source: DEBIAN Type: DSA-187 apache -- several vulnerabilities Source: DEBIAN Type: DSA-188 apache-ssl -- several vulnerabilities Source: DEBIAN Type: DSA-195 apache-perl -- several vulnerabilities Source: CCN Type: OSVDB ID: 9696 Apache HTTP Server htpasswd Local Symlink Arbitrary File Overwrite Source: CCN Type: OSVDB ID: 9697 Apache HTTP Server htdigest Local Symlink Arbitrary File Overwrite Source: CCN Type: Immunix OS Security Advisory IMNX-2000-70-016-01 apache Source: BID Type: Third Party Advisory, VDB Entry 2182 Source: CCN Type: BID-2182 Apache /tmp File Race Vulnerability Source: XF Type: Third Party Advisory, VDB Entry linux-apache-symlink(5926) Source: XF Type: UNKNOWN linux-apache-symlink(5926) | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |