CVE-2006-4248

thttpd on Debian GNU/Linux, and possibly other distributions, allows local users to create or touch arbitrary files via a symlink attack on the start_thttpd temporary file.
Configurations

Configuration 1 (hide)

cpe:2.3:a:acme_labs:thttpd:2.25b:*:*:*:*:*:*:*

History

21 Nov 2024, 00:15

Type Values Removed Values Added
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=396277 - () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=396277 -
References () http://secunia.com/advisories/22712 - () http://secunia.com/advisories/22712 -
References () http://www.debian.org/security/2006/dsa-1205 - () http://www.debian.org/security/2006/dsa-1205 -
References () http://www.securityfocus.com/bid/20891 - () http://www.securityfocus.com/bid/20891 -

Information

Published : 2006-10-31 19:07

Updated : 2024-11-21 00:15


NVD link : CVE-2006-4248

Mitre link : CVE-2006-4248

CVE.ORG link : CVE-2006-4248


JSON object : View

Products Affected

acme_labs

  • thttpd