CVE-2013-0348

Open Source Development Team Sthttpd < 2.26.4 - Access Control

Title source: rule

Description

thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file.

Scores

EPSS 0.0004
EPSS Percentile 10.8%

Classification

CWE
CWE-264
Status draft

Affected Products (12)

open_source_development_team/sthttpd < 2.26.4
open_source_development_team/sthttpd
open_source_development_team/sthttpd
open_source_development_team/sthttpd
open_source_development_team/sthttpd
fedoraproject/fedora
fedoraproject/fedora
gentoo/linux
opensuse/opensuse
opensuse/opensuse
opensuse/opensuse
acme/thttpd

Timeline

Published Dec 13, 2013
Tracked Since Feb 18, 2026