thttpd on Debian GNU/Linux, and possibly other distributions, allows local users to create or touch arbitrary files via a symlink attack on the start_thttpd temporary file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Thttpd | Acme_labs | 2.25b (including) | 2.25b (including) |
Thttpd | Ubuntu | dapper | * |
Thttpd | Ubuntu | devel | * |
Thttpd | Ubuntu | edgy | * |
Thttpd | Ubuntu | feisty | * |
Thttpd | Ubuntu | gutsy | * |
Thttpd | Ubuntu | hardy | * |
Thttpd | Ubuntu | intrepid | * |
Thttpd | Ubuntu | jaunty | * |
Thttpd | Ubuntu | karmic | * |