First published: Wed Feb 14 2001(Updated: )
htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache HTTP Server | =1.3.14 | |
Apache HTTP Server | =2.0-alpha9 | |
Debian GNU/Linux | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0131 is considered a moderate severity vulnerability that allows local users to overwrite arbitrary files.
To mitigate CVE-2001-0131, ensure that the users with access to the htpasswd and htdigest commands are restricted and do not have the ability to create symbolic links.
CVE-2001-0131 affects users of Apache HTTP Server versions 1.3.14, 2.0-alpha9, and specific releases of Debian Linux.
CVE-2001-0131 is associated with a symlink attack that exploits the vulnerabilities in htpasswd and htdigest.
No, CVE-2001-0131 requires local user access to the system to exploit the vulnerability.