Unrated severityNVD Advisory· Published Dec 6, 2001· Updated Apr 16, 2026
CVE-2001-0834
CVE-2001-0834
Description
htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c option to specify an alternate configuration file, which could be used to (1) cause a denial of service (CPU consumption) by specifying a large file such as /dev/zero, or (2) read arbitrary files by uploading an alternate configuration file that specifies the target file.
Affected products
12- cpe:2.3:o:debian:debian_linux:2.2:*:*:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:6.3:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:o:suse:suse_linux:6.3:*:*:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:6.4:*:*:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:7.1:*:*:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:7.2:*:*:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:7.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- distro.conectiva.com.br/atualizacoes/nvdPatchVendor Advisory
- www.debian.org/security/2001/dsa-080nvdPatchVendor Advisory
- marc.infonvd
- sourceforge.net/tracker/index.phpnvd
- www.calderasystems.com/support/security/advisories/CSSA-2001-035.0.txtnvd
- www.linux-mandrake.com/en/security/2001/MDKSA-2001-083.php3nvd
- www.novell.com/linux/security/advisories/2001_035_htdig_txt.htmlnvd
- www.redhat.com/support/errata/RHSA-2001-139.htmlnvd
- www.securityfocus.com/bid/3410nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/7262nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/7263nvd
News mentions
0No linked articles in our index yet.