CVE

Id
3817  
CVE No.
CVE-2001-1013  
Status
Candidate  
Description
Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server.  
Phase
Proposed (20020131)  
Votes
ACCEPT(3) Cole, Frech, Green | MODIFY(2) Cox, Foat | REVIEWING(1) Wall  
Comments
CHANGE> [Foat changed vote from REVIEWING to MODIFY] | Foat> This is only true if "indexes" are NOT enabled and the | "public_html" directory exists for the user. | Cox> The description says "Apache on Red Hat Linux". This issue | affects all versions of Apache that have UserDir enabled, not just | Linux or RHL. In Red Hat Linux we enable UserDir by default, but so | do other distributions.