Wiki Server in Apple Mac OS X 10.5 before 10.5.3 allows remote attackers to obtain sensitive information (user names) by reading the error message produced upon access to a nonexistent blog.
| Software | From | Fixed in |
|---|---|---|
| apple / mac_os_x_server | 10.5.2 | 10.5.2.x |
| apple / mac_os_x_server | 10.4.11 | 10.4.11.x |
| apple / mac_os_x | 10.5.1 | 10.5.1.x |
| apple / mac_os_x_server | 10.5.1 | 10.5.1.x |
| apple / mac_os_x | 10.5 | 10.5.x |
| apple / mac_os_x | 10.5.2 | 10.5.2.x |
| apple / mac_os_x | 10.4.11 | 10.4.11.x |
| apple / mac_os_x_server | 10.5 | 10.5.x |