The remote host appears to be running Apache 1.3.33 or older. There is a local buffer overflow in the 'htpasswd' command in these versions that may allow a local user to gain elevated privileges if 'htpasswd' is run setuid or a remote user to run arbitrary commands remotely if the script is accessible through a CGI. *** Note that OVS solely relied on the version number *** of the remote server to issue this warning. This might *** be a false positive
Make sure htpasswd does not run setuid and is not accessible through any CGI scripts.
Updated on 2015-03-25