PT-2005-2346 · Apache · Apache

Luca Ercoli

·

Publicado

2005-04-27

·

Atualizado

2008-09-10

·

CVE-2005-1344

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Apache version 2.0.52
Description: A buffer overflow issue exists in the htdigest utility of Apache, potentially allowing attackers to execute arbitrary code through a long realm argument. However, since htdigest is typically only accessible locally and not setuid or setgid, there are limited attack vectors that could lead to privilege escalation, unless htdigest is executed from a CGI program.
Recommendations: For Apache version 2.0.52, consider restricting access to the htdigest utility to minimize potential risks, especially if it is executed from a CGI program. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-1344

Produtos afetados

Apache