CVE-2006-4248 Information

Description

thttpd on Debian GNU/Linux and possibly other distributions allows local users to create or touch arbitrary files via a symlink attack on the start_thttpd temporary file.

Reference

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=396277 http://secunia.com/advisories/22712 http://www.debian.org/security/2006/dsa-1205 http://www.securityfocus.com/bid/20891

Share on: