2.6

CVE-2002-1233

A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.

Data is provided by the National Vulnerability Database (NVD)
ApacheHTTP Server Version1.3.17
ApacheHTTP Server Version1.3.17 Editionwin32
ApacheHTTP Server Version1.3.18
ApacheHTTP Server Version1.3.18 Editionwin32
ApacheHTTP Server Version1.3.19
ApacheHTTP Server Version1.3.19 Editionwin32
ApacheHTTP Server Version1.3.20
ApacheHTTP Server Version1.3.20 Editionwin32
ApacheHTTP Server Version1.3.22
ApacheHTTP Server Version1.3.22 Editionwin32
ApacheHTTP Server Version1.3.23
ApacheHTTP Server Version1.3.23 Editionwin32
ApacheHTTP Server Version1.3.24
ApacheHTTP Server Version1.3.24 Editionwin32
ApacheHTTP Server Version1.3.25
ApacheHTTP Server Version1.3.25 Editionwin32
ApacheHTTP Server Version1.3.26
ApacheHTTP Server Version1.3.26 Editionwin32
ApacheHTTP Server Version1.3.27
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.13% 0.335
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.6 1.9 4.9
AV:L/AC:H/Au:N/C:P/I:P/A:N