2.6

CVE-2002-1233

A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheHTTP Server Version1.3.17
ApacheHTTP Server Version1.3.17 Editionwin32
ApacheHTTP Server Version1.3.18
ApacheHTTP Server Version1.3.18 Editionwin32
ApacheHTTP Server Version1.3.19
ApacheHTTP Server Version1.3.19 Editionwin32
ApacheHTTP Server Version1.3.20
ApacheHTTP Server Version1.3.20 Editionwin32
ApacheHTTP Server Version1.3.22
ApacheHTTP Server Version1.3.22 Editionwin32
ApacheHTTP Server Version1.3.23
ApacheHTTP Server Version1.3.23 Editionwin32
ApacheHTTP Server Version1.3.24
ApacheHTTP Server Version1.3.24 Editionwin32
ApacheHTTP Server Version1.3.25
ApacheHTTP Server Version1.3.25 Editionwin32
ApacheHTTP Server Version1.3.26
ApacheHTTP Server Version1.3.26 Editionwin32
ApacheHTTP Server Version1.3.27
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.335
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.6 1.9 4.9
AV:L/AC:H/Au:N/C:P/I:P/A:N