CVE-2006-4248: High severity Acme Labs thttpd vulnerability
Published Oct 31, 2006
·Updated
thttpd on Debian GNU/Linux, and possibly other distributions, allows local users to create or touch arbitrary files via a symlink attack on the startthttpd temporary file.
Affected Software
1 affected component
Acme Labs thttpd=2.25b
Event History
Oct 31, 2006
CVE Published
07:07 PM
Data Sourced
via NVD·07:07 PM
DescriptionSeverityAffected Software
Nov 1, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4248?
CVE-2006-4248 has a moderate severity level as it allows local users to create or touch arbitrary files through a symlink attack.
2
How do I fix CVE-2006-4248?
To fix CVE-2006-4248, users should update thttpd to a version that addresses this vulnerability.
3
Who is affected by CVE-2006-4248?
CVE-2006-4248 primarily affects Debian GNU/Linux systems running thttpd version 2.25b.
4
What type of attack does CVE-2006-4248 involve?
CVE-2006-4248 involves a symlink attack that can exploit temporary file handling in thttpd.
5
Can remote users exploit CVE-2006-4248?
No, CVE-2006-4248 is a local vulnerability that can only be exploited by local users.