Acme Thttpd Insecure Temporary Logfile Creation Vulnerability

Bugtraq ID: 20891
Class: Access Validation Error
CVE: CVE-2006-4248
Remote: No
Local: Yes
Published: Nov 03 2006 12:00AM
Updated: Jan 15 2007 07:40PM
Credit: Marco d'Itri is credited with the discovery of this vulnerability.
Vulnerable: Debian Linux 3.1 sparc
Debian Linux 3.1 s/390
Debian Linux 3.1 ppc
Debian Linux 3.1 mipsel
Debian Linux 3.1 mips
Debian Linux 3.1 m68k
Debian Linux 3.1 ia-64
Debian Linux 3.1 ia-32
Debian Linux 3.1 hppa
Debian Linux 3.1 arm
Debian Linux 3.1 amd64
Debian Linux 3.1 alpha
Debian Linux 3.1
Acme thttpd 2.22
Acme thttpd 2.21 b
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
Acme thttpd 2.21
Acme thttpd 2.20 c
+ SuSE Linux 8.0
Acme thttpd 2.20 b
+ SuSE Linux 7.3
Acme thttpd 2.20
Acme thttpd 2.19
Acme thttpd 2.18
Acme thttpd 2.17
Acme thttpd 2.16
Acme thttpd 2.15
- SuSE Linux 6.4
Acme thttpd 2.14
Acme thttpd 2.13
Acme thttpd 2.12
Acme thttpd 2.11
Acme thttpd 2.10
Acme thttpd 2.0.9
Acme thttpd 2.0.8
Acme thttpd 2.0.7 beta 0.4
Acme thttpd 2.0.7
Acme thttpd 2.0.6
Acme thttpd 2.0.5
+ FREESCO FREESCO 0.3.2
+ FREESCO FREESCO 0.3.1
+ FREESCO FREESCO 0.3 .0
+ FREESCO FREESCO 0.2.7
Acme thttpd 2.0.4
- SuSE Linux 6.3
- SuSE Linux 6.2
Acme thttpd 2.0.3
Acme thttpd 2.0.2
Acme thttpd 2.0.1
Acme thttpd 2.0
Acme thttpd 1.95
Acme thttpd 1.90 a
Acme thttpd 1.0 .x
Acme thttpd 1.0
Acme thttpd 2.1x
+ FreeBSD FreeBSD 4.1.1
+ FreeBSD FreeBSD 3.5.1
- Redhat Linux 7.0
Not Vulnerable: Acme thttpd 2.24
Acme thttpd 2.23 b1
+ S.u.S.E. Linux Personal 9.0
+ S.u.S.E. Linux Personal 8.2
+ SuSE Linux 8.1
Acme thttpd 2.25 b


 

Privacy Statement
Copyright 2010, SecurityFocus