The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HTTP request for the /doc/packages URL.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/84360 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/5276 | vdb entry |
http://www.securityfocus.com/bid/1707 | exploit vdb entry patch vendor advisory |