CVE-2001-1013
Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 65.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 65.56% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- redhat/linux
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0083.htmlVendor Advisory
- http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0087.html
- http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0094.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/213667Vendor Advisory
- http://www.securityfocus.com/bid/3335Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7129
- http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0083.htmlVendor Advisory
- http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0087.html
- http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0094.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/213667Vendor Advisory
- http://www.securityfocus.com/bid/3335Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7129
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.