← Back

CVE-2002-1233

nvd nist
Published: Nov 4, 2002Modified: Apr 16, 2026

JSON object

Loading...
2.6
Vector
AV:L/AC:H/Au:N/C:P/I:P/A:N
Exploitability: 1.9 / Impact: 4.9
Source: NVD

Description

A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.

Affected (19)

Products: Apache: Http Server
1 product
Http Server
Configuration A
19 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 1.3.17
Version 1.3.17
Version 1.3.18
Version 1.3.18
Version 1.3.19
Version 1.3.19
Version 1.3.20
Version 1.3.20
Version 1.3.22
Version 1.3.22
Version 1.3.23
Version 1.3.23
Version 1.3.24
Version 1.3.24
Version 1.3.25
Version 1.3.25
Version 1.3.26
Version 1.3.26
Version 1.3.27

References (16)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.