Mandriva Linux Security Advisory : apache-conf (MDVSA-2009:300-2)
Medium Nessus Plugin ID 42811
SynopsisThe remote Mandriva Linux host is missing a security update.
DescriptionA vulnerability was discovered and corrected in apache-conf :
The Apache HTTP Server enables the HTTP TRACE method per default which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified web client software (CVE-2009-2823).
This update provides a solution to this vulnerability.
Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers.
SolutionUpdate the affected apache-conf package.