CVE-2001-0131: Low severity Apache HTTP Server vulnerability
Published Feb 14, 2001
·Updated
htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
Affected Software
3 affected components
Apache HTTP Server=1.3.14
Apache HTTP Server=2.0-alpha9
Debian Debian Linux=2.2
Remediation
Patch Available
Event History
Feb 14, 2001
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0131?
CVE-2001-0131 is considered a moderate severity vulnerability that allows local users to overwrite arbitrary files.
2
How do I fix CVE-2001-0131?
To mitigate CVE-2001-0131, ensure that the users with access to the htpasswd and htdigest commands are restricted and do not have the ability to create symbolic links.
3
Who is affected by CVE-2001-0131?
CVE-2001-0131 affects users of Apache HTTP Server versions 1.3.14, 2.0-alpha9, and specific releases of Debian Linux.
4
What type of attack is associated with CVE-2001-0131?
CVE-2001-0131 is associated with a symlink attack that exploits the vulnerabilities in htpasswd and htdigest.
5
Can CVE-2001-0131 be exploited remotely?
No, CVE-2001-0131 requires local user access to the system to exploit the vulnerability.