thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file.
2013-12-13T18:07:54.030
2025-04-11T00:51:21.963
Deferred
CVSSv2: 2.1 (LOW)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | open_source_development_team | sthttpd | ≤ 2.26.4 | Yes |
| Application | open_source_development_team | sthttpd | 2.26 | Yes |
| Application | open_source_development_team | sthttpd | 2.26.1 | Yes |
| Application | open_source_development_team | sthttpd | 2.26.2 | Yes |
| Application | open_source_development_team | sthttpd | 2.26.3 | Yes |
| Operating System | fedoraproject | fedora | 17 | Yes |
| Operating System | fedoraproject | fedora | 18 | Yes |
| Operating System | gentoo | linux | * | Yes |
| Operating System | opensuse | opensuse | 12.2 | Yes |
| Operating System | opensuse | opensuse | 12.3 | Yes |
| Operating System | opensuse | opensuse | 13.1 | Yes |
| Application | acme | thttpd | 2.25 | Yes |