|
|
|
Vulnerability Note VU#898480MandrakeSoft Mandrake Linux Apache default configuration sample programs disclose server informationOverviewThe default installation of Apache on MandrakeSoft Mandrake Linux includes sample programs which may unnecessarily disclose information about the server.I. DescriptionMandrakeSoft produces a Linux distribution called Mandrake Linux that includes the Apache web server. The default installation of Apache on Mandrake Linux includes a number of sample programs. When accessed via an HTTP request, these programs display configuration settings such as environment variables, path names, and internal addresses.II. ImpactApache running on a Mandrake Linux system may disclose configuration information via an HTTP request for a sample program.III. SolutionInstall Updated PackageInstall an updated Apache package when available.
References
The CERT Coordination Center thanks ProCheckup Ltd for reporting this vulnerability. This document was written by Art Manion
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||