CVE-2001-0131
published 2001-03-12CVE-2001-0131: htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
PriorityP411low3.3CVSS 2.0
AVLACMAuNCNIPAP
EPSS
2.31%
81.6th percentile
htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| debian | debian_linux | — | — |
CVSS provenance
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-36m7-hm82-xm8q: htpasswd and htdigest in Apache 2
ghsa_unreviewed·2022-04-30
CVE-2001-0131 [LOW] CWE-59 GHSA-36m7-hm82-xm8q: htpasswd and htdigest in Apache 2
htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
GHSA
GHSA-h5gj-xw8w-hmjf: A regression error in the Debian distributions of the apache-ssl package (before 1
ghsa_unreviewed·2022-04-30·CVSS 3.3
CVE-2002-1233 [LOW] GHSA-h5gj-xw8w-hmjf: A regression error in the Debian distributions of the apache-ssl package (before 1
A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.
Red Hat
httpd: allows local users to overwrite arbitrary files via a symlink attack
vendor_redhat·2001-01-10·CVSS 3.3
CVE-2001-0131 [LOW] CWE-59 httpd: allows local users to overwrite arbitrary files via a symlink attack
httpd: allows local users to overwrite arbitrary files via a symlink attack
htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
A flaw was found in Apache httpd. Both htpasswd and htdigest allow local users to overwrite arbitrary files via a symlink attack. The highest threat from this vulnerability is to data integrity.
Statement: All versions of httpd package shipped with Red Hat Products, uses APR's safe temp file creation and therefore they are not affected by this flaw
Package: httpd (Red Hat Enterprise Linux 5) - Not affected
Package: httpd (Red Hat Enterprise Linux 6) - Not affected
Package: httpd (Red Hat Enterprise Linux 7) - Not affected
Package: httpd:2.4/httpd (Red Hat Enterprise Linux 8) - Not a
No detection rules found.
No public exploits indexed.
http://marc.info/?l=bugtraq&m=97916374410647&w=2http://www.debian.org/security/2001/dsa-021http://www.securityfocus.com/bid/2182https://exchange.xforce.ibmcloud.com/vulnerabilities/5926http://marc.info/?l=bugtraq&m=97916374410647&w=2http://www.debian.org/security/2001/dsa-021http://www.securityfocus.com/bid/2182https://exchange.xforce.ibmcloud.com/vulnerabilities/5926
2001-03-12
Published