CVE-2002-1233: Low severity Apache HTTP Server vulnerability
A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1233?
CVE-2002-1233 is classified as a moderate-severity vulnerability as it allows local users to manipulate Apache password files.
How do I fix CVE-2002-1233?
To fix CVE-2002-1233, upgrade the Apache-SSL package to version 1.3.9 for Debian 2.2 or 1.3.26 for Debian 3.0 or later.
Who is affected by CVE-2002-1233?
CVE-2002-1233 affects local users of Debian distributions running specific versions of Apache HTTP Server.
What types of attacks does CVE-2002-1233 allow?
CVE-2002-1233 allows local users to perform a symlink attack on temporary files, potentially gaining access to sensitive password files.
Is CVE-2002-1233 related to any specific versions of Apache?
Yes, CVE-2002-1233 specifically affects Apache versions 1.3.27 and earlier on Debian distributions.