Multiple buffer overflows in the digest authentication functionality in Pavuk 0.9.28-r2 and earlier allow remote attackers to execute arbitrary code.
https://exchange.xforce.ibmcloud.com/vulnerabilities/16807
https://euvd.enisa.europa.eu/vulnerability/EUVD-2004-1434