Security Advisory

CVE-2013-0348

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2013-12-13 18:00:00
Last updated 2024-08-06 14:25:09
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file.