The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.
| Software | From | Fixed in |
|---|---|---|
| apache / http_server | 1.3.1 | 1.3.1.x |
| apache / http_server | 1.3.6 | 1.3.6.x |
| apache / http_server | 1.3.4 | 1.3.4.x |
| apache / http_server | 1.3.18 | 1.3.18.x |
| mandrakesoft / mandrake_single_network_firewall | 7.2 | 7.2.x |
| apache / http_server | 1.3 | 1.3.x |
| apache / http_server | 1.3.12 | 1.3.12.x |
| apache / http_server | 1.3.3 | 1.3.3.x |
| apache / http_server | 1.3.17 | 1.3.17.x |
| apache / http_server | 1.3.9 | 1.3.9.x |
| apache / http_server | 1.3.14 | 1.3.14.x |
| apache / http_server | 1.3.11 | 1.3.11.x |
| mandrakesoft / mandrake_linux_corporate_server | 1.0.1 | 1.0.1.x |
| mandrakesoft / mandrake_linux | 7.1 | 7.1.x |
| mandrakesoft / mandrake_linux | 7.3 | 7.3.x |
| mandrakesoft / mandrake_linux | 8.0 | 8.0.x |