VDB
CVE-2002-1233
CVE-2002-1233
PUBLISHED
CVSS 2.5999999046325684 LOW
A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.
EPSS 0.56% · 44.3th percentile
Risk Scores
CVSS 2.0
2.5999999046325684
EPSS Score
0.56%
44.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| apache | http_server | 1.3.17, 1.3.18, 1.3.18 |
Timeline
- Oct 25, 2002 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- apache-htpasswd-tmpfile-race(10412) vdb
- DSA-188 vendor-advisory
- DSA-195 vendor-advisory
- 20021016 Apache 1.3.26 mailing-list
- http://www.iss.net/security_center/static/10413.php advisory
- http://www.debian.org/security/2002/dsa-187 technical
- http://www.securityfocus.com/bid/5981 technical
- https://nvd.nist.gov/vuln/detail/CVE-2002-1233 advisory
- http://www.securityfocus.com/bid/5990 url