CVE Vulnerabilities

CVE-2001-1433

Published: Dec 29, 2001 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cherokee web server before 0.2.7 does not properly drop root privileges after binding to port 80, which could allow remote attackers to gain privileges via other vulnerabilities.

Affected Software

NameVendorStart VersionEnd Version
Cherokee_httpdCherokee0.1 (including)0.1 (including)
Cherokee_httpdCherokee0.1.5 (including)0.1.5 (including)
Cherokee_httpdCherokee0.1.6 (including)0.1.6 (including)
Cherokee_httpdCherokee0.2 (including)0.2 (including)
Cherokee_httpdCherokee0.2.5 (including)0.2.5 (including)
Cherokee_httpdCherokee0.2.6 (including)0.2.6 (including)

References