Cherokee HTTPD Insecure Privilege Release Vulnerability

BID:3771

Info

Cherokee HTTPD Insecure Privilege Release Vulnerability

Bugtraq ID: 3771
Class: Design Error
CVE: CVE-2001-1433
CVE-2001-1433
Remote: Yes
Local: No
Published: Dec 29 2001 12:00AM
Updated: Mar 19 2015 08:10AM
Credit: This issue was initially publicized in a GOBBLES advisory on December 29th, 2001.
Vulnerable: Cherokee Cherokee HTTPD 0.2.6
- Sun Solaris 8_sparc
- Sun Solaris 7.0
- Sun Solaris 2.6
Cherokee Cherokee HTTPD 0.2.5
- Sun Solaris 8_sparc
- Sun Solaris 7.0
- Sun Solaris 2.6
Cherokee Cherokee HTTPD 0.2
- Sun Solaris 8_sparc
- Sun Solaris 7.0
- Sun Solaris 2.6
Cherokee Cherokee HTTPD 0.1.6
- Sun Solaris 8_sparc
- Sun Solaris 7.0
- Sun Solaris 2.6
Cherokee Cherokee HTTPD 0.1.5
- Sun Solaris 8_sparc
- Sun Solaris 7.0
- Sun Solaris 2.6
Cherokee Cherokee HTTPD 0.1
- Sun Solaris 8_sparc
- Sun Solaris 7.0
- Sun Solaris 2.6
Not Vulnerable: Cherokee Cherokee HTTPD 0.2.7
- Sun Solaris 8_sparc
- Sun Solaris 7.0
- Sun Solaris 2.6

Discussion

Cherokee HTTPD Insecure Privilege Release Vulnerability

Cherokee is a compact web server which provides fast delivery of web content. It is freely available and distributed under the GPL. It runs on Linux and other Unix systems.

Cherokee web server fails to drop root privileges after it binds to port 80.

While this vulnerability is not exploitable in and of itself, Cherokee web server is prone to a number of other issues which may result in a remote root compromise as a consequence of this issue. For example, BugTraq ID 3773 "Cherokee HTTPD Remote Command Execution Vulnerability" and BugTraq ID 3772 "Cherokee HTTPD Directory Traversal Vulnerability" may both be exploited to much greater effect as a result of this issue.

Exploit / POC

Cherokee HTTPD Insecure Privilege Release Vulnerability

There is no exploit code required.

Solution / Fix

Cherokee HTTPD Insecure Privilege Release Vulnerability

Solution:
The vendor has addressed this issue in Cherokee 0.2.7.


Cherokee Cherokee HTTPD 0.1

Cherokee Cherokee HTTPD 0.1.5

Cherokee Cherokee HTTPD 0.1.6

Cherokee Cherokee HTTPD 0.2

Cherokee Cherokee HTTPD 0.2.5

Cherokee Cherokee HTTPD 0.2.6

References

Cherokee HTTPD Insecure Privilege Release Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report