Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 128165 - www-servers/thttpd: htpasswd Arbitrary Privileged Command Execution (CAN-2006-1354)
Summary: www-servers/thttpd: htpasswd Arbitrary Privileged Command Execution (CAN-2006...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: www-servers Herd (OBSOLETE)
URL: http://archives.neohapsis.com/archive...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2006-03-30 13:23 UTC by Eduardo Tongson
Modified: 2007-02-28 22:49 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
htpasswdc_temporaryfix.patch (htpasswdc_temporaryfix.patch,2.20 KB, patch)
2006-03-30 13:25 UTC, Eduardo Tongson
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Eduardo Tongson 2006-03-30 13:23:51 UTC
thttpd contains a flaw that may allow a malicious local user to execute privileged commands. The issue is triggered when a user calls the 'htpasswd' utility but supplies arbitrary commands along with a username to be added to a password file. It is possible that the flaw may allow the user to bypass the required authentication and execute arbitrary programs with privileged access.

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2006-1079
http://marc.theaimsgroup.com/?l=thttpd&m=114153031201867&w=2
http://www.osvdb.org/23828

* Waiting for upstream developer to publish a new/fixed version
* attached a temporary fix (additional input validation)
Comment 1 Eduardo Tongson 2006-03-30 13:25:45 UTC
Created attachment 83458 [details, diff]
htpasswdc_temporaryfix.patch

attached the temporary fix
Comment 2 Tavis Ormandy (RETIRED) gentoo-dev 2006-03-30 13:31:04 UTC
reassigning to www-servers, this is clearly not a security issue.
Comment 3 Thilo Bangert (RETIRED) (RETIRED) gentoo-dev 2007-02-28 22:49:01 UTC
now in version 2.25b-r7 - please test.