2.1
CVSSv2

CVE-2005-3124

Published: 06/11/2005 Updated: 08/03/2011
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

syslogtocern in Acme thttpd prior to 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

acme labs thttpd 2.21b

acme labs thttpd 2.23b1

Vendor Advisories

Javier Fernández-Sanguino Peña from the Debian Security Audit team discovered that the syslogtocern script from thttpd, a tiny webserver, uses a temporary file insecurely, allowing a local attacker to craft a symlink attack to overwrite arbitrary files For the old stable distribution (woody) this problem has been fixed in version 221b-113 For ...