CVE-2013-0348
13.12.2013, 18:07
thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file.Enginsight
Vendor | Product | Version |
---|---|---|
open_source_development_team | sthttpd | 𝑥 ≤ 2.26.4 |
open_source_development_team | sthttpd | 2.26 |
open_source_development_team | sthttpd | 2.26.1 |
open_source_development_team | sthttpd | 2.26.2 |
open_source_development_team | sthttpd | 2.26.3 |
gentoo | linux | * |
opensuse | opensuse | 12.2 |
opensuse | opensuse | 12.3 |
opensuse | opensuse | 13.1 |
acme | thttpd | 2.25:b |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References