CVE-2005-3124: Low severity Acme Labs thttpd vulnerability
Published Nov 6, 2005
·Updated
syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file.
Affected Software
2 affected components
Acme Labs thttpd=2.21b
Acme Labs thttpd=2.23b1
Remediation
Patch Available
Event History
Nov 6, 2005
CVE Published
11:02 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3124?
CVE-2005-3124 is considered a moderate severity vulnerability due to its potential impact on local user permissions.
2
How do I fix CVE-2005-3124?
To fix CVE-2005-3124, upgrade to a version of thttpd later than 2.23b1 that addresses the symlink vulnerability.
3
What are the risks associated with CVE-2005-3124?
The risks of CVE-2005-3124 include unauthorized file writes by local users, potentially leading to data corruption or privilege escalation.
4
Who is affected by CVE-2005-3124?
CVE-2005-3124 affects users running Acme thttpd versions 2.21b and 2.23b1.
5
What kind of attack does CVE-2005-3124 involve?
CVE-2005-3124 involves a symlink attack that allows local users to exploit temporary files to write arbitrary data.