Oval Definition:oval:org.mitre.oval:def:20114
Revision Date:2014-06-23Version:7
Title:DSA-2452-1 apache2 - insecure default configuration
Description:Niels Heinen noticed a security issue with the default Apache configuration on Debian if certain scripting modules like mod_php or mod_rivet are installed. The problem arises because the directory /usr/share/doc, which is mapped to the URL /doc, may contain example scripts that can be executed by requests to this URL. Although access to the URL /doc is restricted to connections from localhost, this still creates security issues in two specific configurations.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2012-0216
DSA-2452-1
Platform(s):Debian GNU/kFreeBSD 6.0
Debian GNU/Linux 6.0
Product(s):apache2
Definition Synopsis
  • Debian 6.0 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND apache2 DPKG is earlier than 0:2.2.16-6+squeeze7
  • BACK