CVE-2006-1079 describes a potential privilege escalation vulnerability in htpasswd, as used in Acme thttpd 2.25b and possibly other products like Apache. Local users could exploit this by injecting shell metacharacters into command-line arguments, which are then processed by a system function. This vulnerability has a CVSS score of 7.2, indicating high severity with local access, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While typically a non-setuid program, the risk increases if htpasswd is configured with sudo privileges or accessed remotely; however, there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.25bCPE matchmatch criteria | cpe:2.3:a:acme_labs:thttpd:2.25b:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.