MacOS X Client Apache Directory Contents Disclosure Vulnerability
BID:3316
Info
MacOS X Client Apache Directory Contents Disclosure Vulnerability
| Bugtraq ID: | 3316 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2001 12:00AM |
| Updated: | Sep 10 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by Jacques Distler <[email protected]> on Sep 10, 2001. |
| Vulnerable: |
Apache Apache 1.3.14 Mac |
| Not Vulnerable: | |
Discussion
MacOS X Client Apache Directory Contents Disclosure Vulnerability
A vulnerability exists when Apache webserver is used with Mac OS X Client.
Due to a flaw in Mac OS file permissions, an issue exists which could disclose the contents of a particular web directory to an unauthorized user. Requesting a URL with the relative path of a '.DS_Store' file, will reveal the contents of the requested directory.
This vulnerability could be used in conjunction with a previously discovered issue (BID 2852), which causes files to be arbitrarily disclosed through mixed case file requests.
A vulnerability exists when Apache webserver is used with Mac OS X Client.
Due to a flaw in Mac OS file permissions, an issue exists which could disclose the contents of a particular web directory to an unauthorized user. Requesting a URL with the relative path of a '.DS_Store' file, will reveal the contents of the requested directory.
This vulnerability could be used in conjunction with a previously discovered issue (BID 2852), which causes files to be arbitrarily disclosed through mixed case file requests.
Exploit / POC
MacOS X Client Apache Directory Contents Disclosure Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
MacOS X Client Apache Directory Contents Disclosure Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
MacOS X Client Apache Directory Contents Disclosure Vulnerability
References:
References: