Vulnerability Description
The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Http Server | 1.3.31 |
References
- http://lists.debian.org/debian-apache/2005/01/msg00076.html
- http://secunia.com/advisories/13925
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18993
- https://usn.ubuntu.com/65-1/
- http://lists.debian.org/debian-apache/2005/01/msg00076.html
- http://secunia.com/advisories/13925
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18993
- https://usn.ubuntu.com/65-1/
FAQ
What is CVE-2004-1387?
CVE-2004-1387 is a vulnerability with a CVSS score of 2.1 (LOW). The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
How severe is CVE-2004-1387?
CVE-2004-1387 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-1387?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server.