Apache <= 1.3.33 htpasswd Local Overflow
Medium Nessus Plugin ID 14771
SynopsisThe remote web server is affected by a buffer overflow vulnerability.
DescriptionThe remote host appears to be running Apache 1.3.33 or older.
There is a local buffer overflow in the 'htpasswd' command in these versions that may allow a local user to gain elevated privileges if 'htpasswd' is run setuid or a remote user to run arbitrary commands remotely if the script is accessible through a CGI.
*** Note that Nessus solely relied on the version number *** of the remote server to issue this warning. This might *** be a false positive
SolutionMake sure htpasswd does not run setuid and is not accessible through any CGI scripts.