search menu icon-carat-right cmu-wordmark

CERT Coordination Center

MandrakeSoft Mandrake Linux Apache default configuration enables Perl ProxyPass server on 8200/tcp

Vulnerability Note VU#927256

Original Release Date: 2001-11-21 | Last Revised: 2002-05-28

Overview

The default installation of Apache on MandrakeSoft Mandrake Linux configures an instance of the server to run apache-mod_perl listening on port 8200/tcp.

Description

MandrakeSoft produces a Linux distribution called Mandrake Linux that includes the Apache web server. The default installation of Apache on Mandrake Linux configures apache-mod_perl to listen on port 8200/tcp. Requests made to the main web server for directories containing Perl programs are proxied internally by Apache to the apache-mod_perl service running on port 8200/tcp. This configuration is called ProxyPass as referenced in Apache's mod_perl performance tuning document. Although all Apache servers on a system share configuration information contained in /etc/httpd/conf/commonhttpd.conf, it is possible that security settings between the two servers are different, and administrators may not expect apache-mod_perl running on port 8200/tcp

Impact

Administrators may not be aware that an HTTPD service is listening on 8200/tcp. Also, it is possible that the security settings for the service on 8200/tcp differ from the service running on 80/tcp.

Solution

Install Updated Package

Install an updated Apache package when available.


Disable Server
Disable the server on 8200/tcp.

Block or Restrict Access
Block or restrict access to port 8200/tcp.

Vendor Information

927256
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

The CERT Coordination Center thanks ProCheckup Ltd for reporting this vulnerability.

This document was written by Art Manion.

Other Information

CVE IDs: None
Severity Metric: 0.21
Date Public: 2001-11-20
Date First Published: 2001-11-21
Date Last Updated: 2002-05-28 21:49 UTC
Document Revision: 19

Sponsored by CISA.