[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250108

 
 

909

 
 

196064

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2002-1233Date: (C)2002-11-04   (M)2023-12-22


A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.6
Exploit Score: 1.9
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: HIGH
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: NONE
  
Reference:
http://marc.info/?l=bugtraq&m=103480856102007&w=2
BID-5981
BID-5990
DSA-187
DSA-188
DSA-195
apache-htdigest-tmpfile-race(10413)
apache-htpasswd-tmpfile-race(10412)

CPE    10
cpe:/a:apache:http_server:1.3.20
cpe:/a:apache:http_server:1.3.23
cpe:/a:apache:http_server:1.3.22
cpe:/a:apache:http_server:1.3.18
...

© SecPod Technologies