The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Http_server | Apache | 1.3 (including) | 1.3 (including) |
| Http_server | Apache | 1.3.1 (including) | 1.3.1 (including) |
| Http_server | Apache | 1.3.3 (including) | 1.3.3 (including) |
| Http_server | Apache | 1.3.4 (including) | 1.3.4 (including) |
| Http_server | Apache | 1.3.6 (including) | 1.3.6 (including) |
| Http_server | Apache | 1.3.9 (including) | 1.3.9 (including) |
| Http_server | Apache | 1.3.11 (including) | 1.3.11 (including) |
| Http_server | Apache | 1.3.12 (including) | 1.3.12 (including) |
| Http_server | Apache | 1.3.14 (including) | 1.3.14 (including) |
| Http_server | Apache | 1.3.17 (including) | 1.3.17 (including) |
| Http_server | Apache | 1.3.18 (including) | 1.3.18 (including) |
| Mandrake_single_network_firewall | Mandrakesoft | 7.2 (including) | 7.2 (including) |