Vulnerability Description
The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Http Server | 1.3 |
| Mandrakesoft | Mandrake Single Network Firewall | 7.2 |
| Mandrakesoft | Mandrake Linux | 7.1 |
| Mandrakesoft | Mandrake Linux Corporate Server | 1.0.1 |
References
- http://www.kb.cert.org/vuls/id/913704PatchUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2001:077-2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8029
- http://www.kb.cert.org/vuls/id/913704PatchUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2001:077-2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8029
FAQ
What is CVE-2001-1449?
CVE-2001-1449 is a vulnerability with a CVSS score of 7.5 (HIGH). The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.
How severe is CVE-2001-1449?
CVE-2001-1449 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-1449?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server, Mandrakesoft Mandrake Single Network Firewall, Mandrakesoft Mandrake Linux, Mandrakesoft Mandrake Linux Corporate Server.