CVE-2013-0348

UNKNOWN
2.1CVSS
Published: 2013-12-13
Updated: 2025-04-11
AI Analysis

Description

thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file.

CVSS Metrics

Vector
AV:L/AC:L/Au:N/C:P/I:N/A:N
Access Vector
local
Access Cmplx
low
Auth
none
Confidentiality
partial
Integrity
none
Availability
none
Weaknesses
CWE-264

Metadata

Primary Vendor
OPEN_SOURCE_DEVELOPMENT_TEAM
Published
12/13/2013
Last Modified
4/11/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

open_source_development_team : sthttpdopen_source_development_team : sthttpdopen_source_development_team : sthttpdopen_source_development_team : sthttpdopen_source_development_team : sthttpdfedoraproject : fedorafedoraproject : fedoragentoo : linuxopensuse : opensuseopensuse : opensuseopensuse : opensuseacme : thttpd

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief