The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.
| Software | From | Fixed in |
|---|---|---|
| apache / http_server | 1.3.12 | 1.3.12.x |
| suse / suse_linux | 6.2 | 6.2.x |
| suse / suse_linux | 6.3 | 6.3.x |
| suse / suse_linux | 6.3-alpha | 6.3-alpha.x |
| suse / suse_linux | 6.0 | 6.0.x |
| suse / suse_linux | 6.1-alpha | 6.1-alpha.x |
| suse / suse_linux | 6.1 | 6.1.x |
| suse / suse_linux | 6.4 | 6.4.x |
| suse / suse_linux | 7.0 | 7.0.x |
| suse / suse_linux | 6.4-alpha | 6.4-alpha.x |