Vulnerability Name: | CVE-2006-1079 (CCN-25217) | ||||||||
Assigned: | 2006-03-05 | ||||||||
Published: | 2006-03-05 | ||||||||
Updated: | 2018-10-18 | ||||||||
Summary: | htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. Note: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Sun Mar 05 2006 - 14:53:43 CST htpasswd bufferoverflow and command execution in thttpd-2.25b. Source: MITRE Type: CNA CVE-2006-1079 Source: MLIST Type: UNKNOWN [thttpd] 20060305 htpasswd.c security issues Source: MLIST Type: UNKNOWN [thttpd] 20060305 Re: htpasswd.c security issues Source: CCN Type: thttpd Web site thttpd Source: OSVDB Type: UNKNOWN 23828 Source: CCN Type: OSVDB ID: 23828 thttpd htpasswd Multiple Local Overflows Source: CCN Type: OSVDB ID: 60381 thttpd htpasswd Command Line Argument Shell Metachracter Arbitrary Command Execution Source: BUGTRAQ Type: UNKNOWN 20060305 htpasswd bufferoverflow and command execution in thttpd-2.25b. Source: BID Type: UNKNOWN 16972 Source: CCN Type: BID-16972 Acme Labs thttpd HTPasswd Multiple Vulnerabilities Source: XF Type: UNKNOWN thttpd-command-line-bo(25217) Source: XF Type: UNKNOWN thttpd-command-line-bo(25217) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |