CVE-2006-1078
Summary
| CVE | CVE-2006-1078 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-03-09 00:02:00 UTC |
| Updated | 2023-11-28 17:15:00 UTC |
| Description | Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Neohapsis Archives - Full Disclosure List - #0547 - [Full-Disclosure] FlowSecurity.org: Local Stack Overflow on htpasswd apache 1.3.31 advsory. | FULLDISC | archives.neohapsis.com | |
| 41279 – Apache 1.3.37 htpasswd is vulnerable to buffer overflow vulnerability | MISC | issues.apache.org | |
| Acme Labs thttpd HTPasswd Multiple Vulnerabilities | BID | www.securityfocus.com | |
| [Full-disclosure] Apache 1.3.37 htpasswd buffer overflow vulnerability | FULLDISC | lists.grok.org.uk | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Bugtraq: Re: local buffer overflow in htpasswd for apache 1.3.31 not fixed in .33? | BUGTRAQ | seclists.org | |
| m-privacy TightGate-Pro Code Execution / Insecure Permissions ≈ Packet Storm | packetstormsecurity.com | ||
| Bug 31975 - httpd-1.3.33: buffer overflow in htpasswd if called with long arguments | MISC | issues.apache.org | |
| Page not found – Security Express | FULLDISC | www.security-express.com | |
| '[THTTPD] htpasswd.c security issues.' - MARC | MLIST | marc.info | |
| 'Re: [THTTPD] htpasswd.c security issues.' - MARC | MLIST | marc.info | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Full Disclosure: SEC Consult SA-20231122 :: Multiple Vulnerabilities in m-privacy TightGate-Pro | seclists.org | ||
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.