CVE-2001-0834
5 documents5 sources
Severity
6.4MEDIUM
EPSS
2.5%
top 14.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 6
Latest updateApr 30
Description
htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c option to specify an alternate configuration file, which could be used to (1) cause a denial of service (CPU consumption) by specifying a large file such as /dev/zero, or (2) read arbitrary files by uploading an alternate configuration file that specifies the target file.
CVSS vector
AV:N/AC:L/C:P/I:N/A:PExploitability: 10.0 | Impact: 4.9
Affected Packages3 packages
Also affects: Debian Linux 2.2