CVE-2006-1078
Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.54%
- Percentil entre todas las CVEs puntuadas: 43
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0547.html
- http://issues.apache.org/bugzilla/show_bug.cgi?id=31975
- http://issues.apache.org/bugzilla/show_bug.cgi?id=41279
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051562.html
- http://marc.info/?l=thttpd&m=114153031201867&w=2
- http://marc.info/?l=thttpd&m=114154083000296&w=2
- http://packetstormsecurity.com/files/175949/m-privacy-TightGate-Pro-Code-Execution-Insecure-Permissions.html
- http://seclists.org/bugtraq/2004/Oct/0359.html
- http://seclists.org/fulldisclosure/2023/Nov/13
- http://www.security-express.com/archives/fulldisclosure/2004-10/1117.html
- http://www.securityfocus.com/archive/1/426823/100/0/threaded
- http://www.securityfocus.com/bid/16972
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25216
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31236
- http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0547.html
- http://issues.apache.org/bugzilla/show_bug.cgi?id=31975
- http://issues.apache.org/bugzilla/show_bug.cgi?id=41279
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051562.html
- http://marc.info/?l=thttpd&m=114153031201867&w=2
- http://marc.info/?l=thttpd&m=114154083000296&w=2
- http://packetstormsecurity.com/files/175949/m-privacy-TightGate-Pro-Code-Execution-Insecure-Permissions.html
- http://seclists.org/bugtraq/2004/Oct/0359.html
- http://seclists.org/fulldisclosure/2023/Nov/13
- http://www.security-express.com/archives/fulldisclosure/2004-10/1117.html
- http://www.securityfocus.com/archive/1/426823/100/0/threaded
- http://www.securityfocus.com/bid/16972
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25216
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31236
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-1078",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2006-1078",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-01-16T20:01:08.855744Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.4,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.5
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-03-09T00:02:00.000",
"references": [
{
"url": "http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0547.html",
"source": "cve@mitre.org"
},
{
"url": "http://issues.apache.org/bugzilla/show_bug.cgi?id=31975",
"source": "cve@mitre.org"
},
{
"url": "http://issues.apache.org/bugzilla/show_bug.cgi?id=41279",
"source": "cve@mitre.org"
},
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051562.html",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=thttpd&m=114153031201867&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=thttpd&m=114154083000296&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.com/files/175949/m-privacy-TightGate-Pro-Code-Execution-Insecure-Permissions.html",
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/bugtraq/2004/Oct/0359.html",
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/fulldisclosure/2023/Nov/13",
"source": "cve@mitre.org"
},
{
"url": "http://www.security-express.com/archives/fulldisclosure/2004-10/1117.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/426823/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/16972",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/25216",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/31236",
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0547.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://issues.apache.org/bugzilla/show_bug.cgi?id=31975",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://issues.apache.org/bugzilla/show_bug.cgi?id=41279",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051562.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=thttpd&m=114153031201867&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=thttpd&m=114154083000296&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://packetstormsecurity.com/files/175949/m-privacy-TightGate-Pro-Code-Execution-Insecure-Permissions.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/bugtraq/2004/Oct/0359.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2023/Nov/13",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.security-express.com/archives/fulldisclosure/2004-10/1117.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/426823/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/16972",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/25216",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/31236",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included."
},
{
"lang": "es",
"value": "Múltiples desbordamientos de búfer en htpasswd, como se utiliza en Acme thttpd 2.25b y posiblemente otros productos tales como Apache, podrían permitir a usuarios locales obtener privilegios a través de (1) un argumento de línea de comando largo y (2) una línea larga en un archivo. NOTA: debido a que htpasswd normalmente es instalado como un programa no setuid y la explotación es a través de las opciones de línea de comando, quizás esta cuestión no debería incluirse en la CVE. Sin embargo, si hay algunas configuraciones típicas o recomendadas que utilizan htpasswd con privilegios de sudo o productos comunes que acceden remotamente a htpasswd, entonces tal vez debería ser incluido."
}
],
"lastModified": "2026-06-16T22:21:58.860",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:acme_labs:thttpd:2.25b:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4BE72B09-4A62-4C57-9695-AB359F6C0A2E"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}