Summary
The remote host is missing an update to apache
announced via advisory DSA 021-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20021-1
Insight
WireX have found some occurrences of insecure opening of temporary files in htdigest and htpasswd. Both programs are not installed setuid or setgid and thus the impact should be minimal. The Apache group has released another security bugfix which fixes a vulnerability in mod_rewrite which may result the remote attacker to access arbitrary files on the web server.
We recommend you upgrade your Apache packages.
Severity
Classification
-
CVE CVE-2001-0131 -
CVSS Base Score: 1.2
AV:L/AC:H/Au:N/C:N/I:P/A:N
Related Vulnerabilities