LWN.net Logo

thttpd: insecure temporary files

Package(s):thttpd CVE #(s):CVE-2006-4248
Created:November 3, 2006 Updated:December 1, 2006
Description: Marco d'Itri discovered that thttpd, a small, fast and secure webserver, makes use of insecure temporary files when its logfiles are rotated, which might lead to a denial of service through a symlink attack.
Alerts:
Debian DSA-1205-2 2006-12-01
Debian DSA-1205-1 2006-11-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds