CVE
- Id
- 3817
- CVE No.
- CVE-2001-1013
- Status
- Candidate
- Description
- Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server.
- Phase
- Proposed (20020131)
- Votes
- ACCEPT(3) Cole, Frech, Green | MODIFY(2) Cox, Foat | REVIEWING(1) Wall
- Comments
- CHANGE> [Foat changed vote from REVIEWING to MODIFY] | Foat> This is only true if "indexes" are NOT enabled and the | "public_html" directory exists for the user. | Cox> The description says "Apache on Red Hat Linux". This issue | affects all versions of Apache that have UserDir enabled, not just | Linux or RHL. In Red Hat Linux we enable UserDir by default, but so | do other distributions.