Back to search
CVE-2013-0348
Published: Dec 13, 2013
Modified: Aug 6, 2024
PUBLISHED
Description
thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20130222 Re: CVE request: sthttpd world-redable logdir
mailing-list
x_refsource_MLIST
https://bugs.gentoo.org/show_bug.cgi?id=458896
x_refsource_CONFIRM
openSUSE-SU-2014:0021
vendor-advisory
x_refsource_SUSE
https://bugzilla.redhat.com/show_bug.cgi?id=924857
x_refsource_CONFIRM
openSUSE-SU-2013:1862
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now