PT-2013-2247 · Sthttpd+1 · Thttpd
Published
2013-12-13
·
Updated
2024-06-15
·
CVE-2013-0348
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
sthttpd versions prior to 2.26.4-r2
thttpd version 2.25b
Description
The issue allows local users to obtain sensitive information by reading the /var/log/thttpd.log file due to world-readable permissions.
Recommendations
For sthttpd versions prior to 2.26.4-r2, update to version 2.26.4-r2 or later.
For thttpd version 2.25b, consider restricting access to the /var/log/thttpd.log file until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Thttpd