CVE-2000-1206: Medium severity Apache HTTP Server vulnerability
Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using modrewrite, or modvhostalias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache httpdto a version that resolves this vulnerability.Fixed in 1.3.11 - Configuration
Disable mod_rewrite and/or mod_vhost_alias or avoid mass virtual hosting configurations until Apache httpd is upgraded to 1.3.11.
Apache httpd mass virtual hosting (mod_rewrite / mod_vhost_alias) = disable/avoid - Operational
Inventory servers to identify any running Apache httpd versions before 1.3.11 and prioritize applying the upgrade or configuration changes on affected hosts.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-1206?
CVE-2000-1206 is considered a high severity vulnerability due to the potential for unauthorized file retrieval.
How do I fix CVE-2000-1206?
To fix CVE-2000-1206, upgrade Apache HTTP Server to version 1.3.11 or later.
Which versions of Apache are affected by CVE-2000-1206?
CVE-2000-1206 affects Apache HTTP Server versions 1.3.9 and 1.3.10.
Can remote attackers exploit CVE-2000-1206?
Yes, CVE-2000-1206 allows remote attackers to exploit the vulnerability and retrieve arbitrary files.
What configurations are vulnerable in CVE-2000-1206?
CVE-2000-1206 is vulnerable when Apache is configured for mass virtual hosting using mod_rewrite or mod_vhost_alias.