mod_usertrack in Apache 1.3.11 through 1.3.20 generates predictable
session IDs (host IP, system time, PID), which "allows local users to
obtain session IDs and bypass authentication when these session IDs are
used for authentication". Red Hat states "This is not a security issue.
The mod_usertrack cookies are not designed to be used for
authentication." NVD affected range is 1.3.11-1.3.20, far below the
shipped 2.4.68. Debian: unimportant.
https://security-tracker.debian.org/tracker/CVE-2001-1534