The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HTTP request for the /doc/packages URL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Suse_linux | Suse | 6.3 (including) | 6.3 (including) |
Suse_linux | Suse | 6.4 (including) | 6.4 (including) |