7.2
CVSSv2

CVE-2006-4248

Published: 31/10/2006 Updated: 05/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

thttpd on Debian GNU/Linux, and possibly other distributions, allows local users to create or touch arbitrary files via a symlink attack on the start_thttpd temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

acme labs thttpd 2.25b

Vendor Advisories

The original advisory for this issue didn't contain fixed packages for all supported architectures which are corrected in this update For reference please find below the original advisory text: Marco d'Itri discovered that thttpd, a small, fast and secure webserver, makes use of insecure temporary files when its logfiles are rotated, which might ...