search menu icon-carat-right cmu-wordmark

CERT Coordination Center

MandrakeSoft Mandrake Linux Apache default configuration sample programs disclose server information

Vulnerability Note VU#898480

Original Release Date: 2001-11-20 | Last Revised: 2002-12-06

Overview

The default installation of Apache on MandrakeSoft Mandrake Linux includes sample programs which may unnecessarily disclose information about the server.

Description

MandrakeSoft produces a Linux distribution called Mandrake Linux that includes the Apache web server. The default installation of Apache on Mandrake Linux includes a number of sample programs. When accessed via an HTTP request, these programs display configuration settings such as environment variables, path names, and internal addresses.

Impact

Apache running on a Mandrake Linux system may disclose configuration information via an HTTP request for a sample program.

Solution

Install Updated Package

Install an updated Apache package when available.

Remove Vulnerable Programs
Remove the sample programs or block access to them using UNIX file permissions.

Vendor Information

898480
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

The CERT Coordination Center thanks ProCheckup Ltd for reporting this vulnerability.

This document was written by Art Manion

Other Information

CVE IDs: None
Severity Metric: 3.15
Date Public: 2001-11-20
Date First Published: 2001-11-20
Date Last Updated: 2002-12-06 18:10 UTC
Document Revision: 15

Sponsored by CISA.