CVE-2001-0834

5 documents5 sources
Severity
6.4MEDIUM
EPSS
2.5%
top 14.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 6
Latest updateApr 30

Description

htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c option to specify an alternate configuration file, which could be used to (1) cause a denial of service (CPU consumption) by specifying a large file such as /dev/zero, or (2) read arbitrary files by uploading an alternate configuration file that specifies the target file.

CVSS vector

AV:N/AC:L/C:P/I:N/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages3 packages

NVDhtdig/htdig3.1.5
NVDconectiva/linux4 versions+3
NVDsuse/suse_linux6 versions+5

Also affects: Debian Linux 2.2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-v6hf-54vc-wr5c: htsearch CGI program in htdig (ht://Dig) 32022-04-30
CVEList
CVE-2001-0834: htsearch CGI program in htdig (ht://Dig) 32002-03-09

📋Vendor Advisories

1
Red Hat
security flaw2001-10-07

💬Community

1
Bugzilla
CVE-2001-0834 security flaw2018-08-16