CVE-2004-1387: Low severity Apache HTTP Server vulnerability
Published Dec 31, 2004
·Updated
The checkforensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
Affected Software
1 affected component
Apache HTTP Server=1.3.31
Event History
Dec 31, 2004
CVE Published
05:00 AM
Feb 6, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1387?
CVE-2004-1387 has a medium severity rating due to the potential for local users to exploit the vulnerability through symlink attacks.
2
How do I fix CVE-2004-1387?
To resolve CVE-2004-1387, it is recommended to upgrade the Apache HTTP Server to version 1.3.32 or later.
3
What systems are affected by CVE-2004-1387?
CVE-2004-1387 specifically affects the Apache HTTP Server version 1.3.31.
4
What type of attack does CVE-2004-1387 allow?
CVE-2004-1387 allows local users to perform a symlink attack that can overwrite or create arbitrary files.
5
Is CVE-2004-1387 still a concern today?
CVE-2004-1387 is less of a concern today as the affected software version is outdated, but it remains a vulnerability in any systems still using it.