CVE

Id
2952  
CVE No.
CVE-2001-0131  
Status
Candidate  
Description
htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.  
Phase
Modified (20010430-01)  
Votes
ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Christey, Magdych, Wall  
Comments
Frech> XF:linux-apache-symlink(5926) | Christey> XF:linux-apache-symlink | URL:http://xforce.iss.net/static/5926.php | Christey> http://archives.neohapsis.com/archives/vendor/2001-q1/0019.html | Christey> This item may have been re-introduced into the Apache source | code sometime during 2002; CVE-2002-1233 has been created for | that version, which affects Apache 1.3.27 and other versions. | Christey> As a further clarification, CVE-2002-1233 is *only* for the | Debian-specific regression error. | Christey> DEBIAN:DSA-195 | URL:http://www.debian.org/security/2002/dsa-195