CVE-2001-0892: Medium severity acme thttpd vulnerability
Published Nov 13, 2001
·Updated
Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.
Affected Software
1 affected component
ACME Thttpd<=2.22
Event History
Nov 13, 2001
CVE Published
05:00 AM
Feb 2, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0892?
CVE-2001-0892 is considered a high severity vulnerability due to its ability to expose sensitive files.
2
How do I fix CVE-2001-0892?
To fix CVE-2001-0892, you should update Acme Thttpd to version 2.22 or later.
3
What are the exploitation methods for CVE-2001-0892?
Remote attackers can exploit CVE-2001-0892 by sending a GET request with a trailing slash to access sensitive files.
4
What impact does CVE-2001-0892 have on webserver security?
CVE-2001-0892 can lead to unauthorized disclosure of sensitive files, risking user data and server integrity.
5
Which versions of Acme Thttpd are vulnerable to CVE-2001-0892?
Acme Thttpd versions before 2.22 with the chroot option enabled are vulnerable to CVE-2001-0892.