2.6

CVE-2002-1233

A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ HTTP Server Version 1.3.17
Apache ≫ HTTP Server Version 1.3.17 Edition win32
Apache ≫ HTTP Server Version 1.3.18
Apache ≫ HTTP Server Version 1.3.18 Edition win32
Apache ≫ HTTP Server Version 1.3.19
Apache ≫ HTTP Server Version 1.3.19 Edition win32
Apache ≫ HTTP Server Version 1.3.20
Apache ≫ HTTP Server Version 1.3.20 Edition win32
Apache ≫ HTTP Server Version 1.3.22
Apache ≫ HTTP Server Version 1.3.22 Edition win32
Apache ≫ HTTP Server Version 1.3.23
Apache ≫ HTTP Server Version 1.3.23 Edition win32
Apache ≫ HTTP Server Version 1.3.24
Apache ≫ HTTP Server Version 1.3.24 Edition win32
Apache ≫ HTTP Server Version 1.3.25
Apache ≫ HTTP Server Version 1.3.25 Edition win32
Apache ≫ HTTP Server Version 1.3.26
Apache ≫ HTTP Server Version 1.3.26 Edition win32
Apache ≫ HTTP Server Version 1.3.27
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.56% 0.423
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.6 1.9 4.9
AV:L/AC:H/Au:N/C:P/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.debian.org/security/2002/dsa-187
http://www.debian.org/security/2002/dsa-188
http://www.debian.org/security/2002/dsa-195
http://marc.info/?l=bugtraq&m=103480856102007&w=2
http://www.iss.net/security_center/static/10412.php
http://www.iss.net/security_center/static/10413.php
Vendor Advisory
http://www.securityfocus.com/bid/5981
http://www.securityfocus.com/bid/5990