CVE-2006-1078

8.4 HIGH
Published: March 09, 2006 Modified: April 16, 2026
View on NVD

Description

Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://issues.apache.org/bugzilla/show_bug.cgi?id=31975
Source: af854a3a-2127-422b-91ae-364da2661108
http://issues.apache.org/bugzilla/show_bug.cgi?id=41279
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=thttpd&m=114153031201867&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=thttpd&m=114154083000296&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://seclists.org/bugtraq/2004/Oct/0359.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://seclists.org/fulldisclosure/2023/Nov/13
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/426823/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/16972
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/25216
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/31236
Source: af854a3a-2127-422b-91ae-364da2661108

28 reference(s) from NVD

Quick Stats

CVSS v3 Score
8.4 / 10.0
EPSS (Exploit Probability)
0.2%
41th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

acme_labs