oss-sec mailing list archives

CVE request: webfs world-readable log


From: Agostino Sarubbo <ago () gentoo org>
Date: Fri, 22 Feb 2013 14:04:54 +0100

Hello,

webfs[1], a Lightweight HTTP server for static content creates its log with 
world-readable permission:

# ls /var/log/webfsd.log -la
-rw-r--r-- 1 root root 0 Feb 22 14:02 /var/log/webfsd.log

Please assign a CVE.
-- 
Agostino Sarubbo
Gentoo Linux Developer


Current thread: