GLSA Bodhisattva
Joined: 13 Jun 2003 Posts: 4087 Location: Dresden, Germany
|
Posted: Fri Sep 24, 2004 7:30 am Post subject: [ GLSA 200409-33 ] Apache: Exposure of protected directories |
|
|
Gentoo Linux Security Advisory
Title: Apache: Exposure of protected directories (GLSA 200409-33)
Severity: low
Exploitable: remote
Date: September 24, 2004
Updated: December 30, 2007
Bug(s): #64804
ID: 200409-33
Synopsis
A bug in the way Apache handles the Satisfy directive can lead to the
exposure of protected directories to unauthorized users.
Background
The Apache HTTP server is one of most popular web servers on the Internet.
Affected Packages
Package: www-servers/apache
Vulnerable: = 2.0.51
Unaffected: >= 2.0.51-r1
Unaffected: < 2.0.51
Architectures: All supported architectures
Description
A bug in the way Apache handles the Satisfy directive, which is used to
require that certain conditions (client host, client authentication, etc)
be met before access to a certain directory is granted, could allow the
exposure of protected directories to unauthorized clients.
Impact
Directories containing protected data could be exposed to all visitors to
the webserver.
Workaround
There is no known workaround at this time.
Resolution
All Apache users should upgrade to the latest version:
Code: | # emerge sync
# emerge -pv ">=www-servers/apache-2.0.51-r1"
# emerge ">=www-servers/apache-2.0.51-r1" |
References
Apache Bug #31315
CAN-2004-0811
Last edited by GLSA on Fri Sep 26, 2014 4:17 am; edited 10 times in total |
|