MidnightBSD

Advisories for open_source_development_team

CVE-2013-0348 LOW

thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
fedoraproject fedora 17
open_source_development_team sthttpd 2.26.1
open_source_development_team sthttpd 2.26.3
gentoo linux *
opensuse opensuse 12.2
fedoraproject fedora 18
open_source_development_team sthttpd 2.26
opensuse opensuse 13.1
opensuse opensuse 12.3
acme thttpd 2.25
open_source_development_team sthttpd *
open_source_development_team sthttpd 2.26.2