CVE Vulnerabilities

CVE-2001-1433

Published: Dec 29, 2001 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Cherokee web server before 0.2.7 does not properly drop root privileges after binding to port 80, which could allow remote attackers to gain privileges via other vulnerabilities.

Affected Software

Name Vendor Start Version End Version
Cherokee_httpd Cherokee 0.1 (including) 0.1 (including)
Cherokee_httpd Cherokee 0.1.5 (including) 0.1.5 (including)
Cherokee_httpd Cherokee 0.1.6 (including) 0.1.6 (including)
Cherokee_httpd Cherokee 0.2 (including) 0.2 (including)
Cherokee_httpd Cherokee 0.2.5 (including) 0.2.5 (including)
Cherokee_httpd Cherokee 0.2.6 (including) 0.2.6 (including)

References