LWN.net Logo

thttpd: insecure temp file

Package(s):thttpd CVE #(s):CVE-2005-3124
Created:November 4, 2005 Updated:November 9, 2005
Description: Javier Fernández-Sanguino Peña from the Debian Security Audit team discovered that the syslogtocern script from thttpd, a tiny webserver, uses a temporary file insecurely, allowing a local attacker to craft a symlink attack to overwrite arbitrary files.
Alerts:
Debian DSA-883-1 2005-11-04

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds