Back

LOW

httpd: allows local users to overwrite arbitrary files via a symlink attack

Published Feb 14, 2001

Description

htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.

Affected products

Remediation

Red Hat statement

All versions of httpd package shipped with Red Hat Products, uses APR's safe temp file creation and therefore they are not affected by this flaw

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 14, 2001
Updated Aug 8, 2024
Reserved Feb 6, 2001
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Jan 10, 2001