SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#913704

MandrakeSoft Mandrake Linux Apache default configuration enables directory indexing

Overview

The default installation of Apache on MandrakeSoft Mandrake Linux enables directory indexing on directories that may unnecessarily disclose information about the server.

I. Description

MandrakeSoft produces a Linux distribution called Mandrake Linux that includes the Apache web server. The default installation of Apache on Mandrake Linux enabes indexing at the root of the web server. Most of the directories of the web server are therefore browsable, and any new directories will inherit the index setting. The server may disclose directory structure, file names and locations, and possibly file contents.

II. Impact

Apache running on a Mandrake Linux system may disclose directory structure, file names and locations, and possibly the contents of files.

III. Solution

Install Updated Package

Install an updated Apache package when available.
Disable Indexing
Disable indexing where desired by modifying /etc/httpd/conf/httpd.conf. Note that the following example disables indexing for the entire default web site: /var/www/ and all subdirectories.



http://www.procheckup.com/vuln.html

Credit

The CERT Coordination Center thanks ProCheckup Ltd for reporting this vulnerability.

This document was written by Art Manion.

Other Information

Date Public:2001-11-20
Date First Published:2001-11-21
Date Last Updated:2002-12-06
CERT Advisory: 
CVE-ID(s): 
NVD-ID(s): 
US-CERT Technical Alerts: 
Metric:0.21
Document Revision:18

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2001 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader