CVE-2002-1658
Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow attackers to execute arbitrary code via a long user argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
- Affected products
- Apache
- Apache Http Server
- = 1.3.1, 1.3.3, 1.3.4, 1.3.6, 1.3.9, 1.3.11, 1.3.12, 1.3.14, 1.3.17, 1.3.18, 1.3.19, 1.3.20, 1.3.22, 1.3.23, 1.3.24, 1.3.25, 1.3.26, 1.3.27
- Fix
- Available
- CVSS 2.0
- 4.6 MEDIUM
- EPSS
- 1.1% (61th percentile)
- NVD status
- Modified
- Published
- 2005-04-27
CVE-2002-1658 at NVD
No indexed exploits for CVE-2002-1658 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2002-1658 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.