CVE-2013-0348

sthttpd < 2.26.4 - Sensitive Information Exposure via World-Readable Log File

Title source: llm
STIX 2.1

Description

thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file.

References (6)

Core 6

Scores

EPSS 0.0004
EPSS Percentile 11.3%

Details

CWE
CWE-264
Status published
Products (12)
acme/thttpd 2.25 b
fedoraproject/fedora 17
fedoraproject/fedora 18
gentoo/linux
open_source_development_team/sthttpd 2.26
open_source_development_team/sthttpd 2.26.1
open_source_development_team/sthttpd 2.26.2
open_source_development_team/sthttpd 2.26.3
open_source_development_team/sthttpd < 2.26.4
opensuse/opensuse 12.2
... and 2 more
Published Dec 13, 2013
Tracked Since Feb 18, 2026