First published: Fri Mar 22 2013(Updated: )
Agostino Sarubbo reported on the oss-security mailing list [1] that, on Gentoo, thttpd log file is world-readable. This could allow an unprivileged user to read the log file. References: [1] <a href="http://www.openwall.com/lists/oss-security/2013/02/22/18">http://www.openwall.com/lists/oss-security/2013/02/22/18</a> [2] <a href="https://bugs.gentoo.org/show_bug.cgi?id=458896">https://bugs.gentoo.org/show_bug.cgi?id=458896</a> [3] <a href="http://www.openwall.com/lists/oss-security/2013/02/23/7">http://www.openwall.com/lists/oss-security/2013/02/23/7</a> Relevant (sthttpd) upstream patch: [4] <a href="http://opensource.dyc.edu/gitweb/?p=sthttpd.git;a=commit;h=d2e186dbd58d274a0dea9b59357edc8498b5388d">http://opensource.dyc.edu/gitweb/?p=sthttpd.git;a=commit;h=d2e186dbd58d274a0dea9b59357edc8498b5388d</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Open Source Development Team Sthttpd | <=2.26.4 | |
Open Source Development Team Sthttpd | =2.26 | |
Open Source Development Team Sthttpd | =2.26.1 | |
Open Source Development Team Sthttpd | =2.26.2 | |
Open Source Development Team Sthttpd | =2.26.3 | |
Fedoraproject Fedora | =17 | |
Fedoraproject Fedora | =18 | |
Gentoo Linux | ||
openSUSE openSUSE | =12.2 | |
openSUSE openSUSE | =12.3 | |
openSUSE openSUSE | =13.1 | |
Acme Thttpd | =2.25-b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.