|
|
|
|
|
|
|
| |
Apache <= 1.3.33 htpasswd Local Overflow |
|
| This script is Copyright (C) 2004-2010 David Maciejak |
|
|
| Family | Web Servers |
| Nessus Plugin ID | 14771 (apache_htpasswd_overflow.nasl) |
| Bugtraq ID | 13777 13778
|
| CVE ID |
|
|
| Description: |
Synopsis :
The remote web server is affected by a buffer overflow vulnerability.
Description :
The remote host appears to be running Apache 1.3.33 or older.
There is a local buffer overflow in the 'htpasswd' command in these
versions that may allow a local user to gain elevated privileges if
'htpasswd' is run setuid or a remote user to run arbitrary commands
remotely if the script is accessible through a CGI.
*** Note that Nessus solely relied on the version number
*** of the remote server to issue this warning. This might
*** be a false positive
See also :
http://archives.neohapsis.com/archives/bugtraq/2004-10/0345.html
http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0547.html
Solution :
Make sure htpasswd does not run setuid and is not accessible
through any CGI scripts.
Risk factor :
Medium / CVSS Base Score : 6.8
(CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
|
|
|
|
|
|