CVE-2007-0664: Medium severity Acme Labs thttpd vulnerability
Published Feb 2, 2007
·Updated
thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files.
Affected Software
1 affected component
Acme Labs thttpd<=2.24
Remediation
Patch Available
Patch Available
Patch Available
Event History
Feb 2, 2007
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0664?
CVE-2007-0664 is considered a high-severity vulnerability due to its potential for arbitrary file reading by remote attackers.
2
How do I fix CVE-2007-0664?
To fix CVE-2007-0664, you should upgrade thttpd to version 2.25b-r6 or later.
3
What systems are affected by CVE-2007-0664?
CVE-2007-0664 affects thttpd versions before 2.25b-r6, particularly those running on Gentoo Linux.
4
What are the consequences of CVE-2007-0664?
The main consequence of CVE-2007-0664 is the potential for an attacker to read sensitive files on the system.
5
When was CVE-2007-0664 reported?
CVE-2007-0664 was reported in January 2007.