CVE
- Id
- 2952
- CVE No.
- CVE-2001-0131
- Status
- Candidate
- Description
- htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
- Phase
- Modified (20010430-01)
- Votes
- ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Christey, Magdych, Wall
- Comments
- Frech> XF:linux-apache-symlink(5926) | Christey> XF:linux-apache-symlink | URL:http://xforce.iss.net/static/5926.php | Christey> http://archives.neohapsis.com/archives/vendor/2001-q1/0019.html | Christey> This item may have been re-introduced into the Apache source | code sometime during 2002; CVE-2002-1233 has been created for | that version, which affects Apache 1.3.27 and other versions. | Christey> As a further clarification, CVE-2002-1233 is *only* for the | Debian-specific regression error. | Christey> DEBIAN:DSA-195 | URL:http://www.debian.org/security/2002/dsa-195