GLSA-200409-33 : Apache: Exposure of protected directories
High Nessus Plugin ID 14811
SynopsisThe remote Gentoo host is missing one or more security-related patches.
DescriptionThe remote host is affected by the vulnerability described in GLSA-200409-33 (Apache: Exposure of protected directories)
A bug in the way Apache handles the Satisfy directive, which is used to require that certain conditions (client host, client authentication, etc) be met before access to a certain directory is granted, could allow the exposure of protected directories to unauthorized clients.
Directories containing protected data could be exposed to all visitors to the webserver.
There is no known workaround at this time.
SolutionAll Apache users should upgrade to the latest version:
# emerge sync # emerge -pv '>=www-servers/apache-2.0.51-r1' # emerge '>=www-servers/apache-2.0.51-r1'