CVE-2001-1433

critical

Description

Cherokee web server before 0.2.7 does not properly drop root privileges after binding to port 80, which could allow remote attackers to gain privileges via other vulnerabilities.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/7797

http://www.kb.cert.org/vuls/id/245795

Details

Source: Mitre, NVD

Published: 2001-12-29

Updated: 2017-07-11

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical