Bug 201592 - CVE-2006-3835 tomcat directory listing leak (RHAPS2)
Summary: CVE-2006-3835 tomcat directory listing leak (RHAPS2)
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Red Hat Application Server
Classification: Retired
Component: tomcat
Version: 2.0
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Fernando Nasser
QA Contact:
URL:
Whiteboard: impact=moderate,source=cve,reported=2...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2006-08-07 17:47 UTC by Marcel Holtmann
Modified: 2007-04-18 17:47 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2006-08-18 20:23:10 UTC
Embargoed:


Attachments (Terms of Use)

Description Marcel Holtmann 2006-08-07 17:47:31 UTC
ScanAlert Security Advisory:

http://archives.neohapsis.com/archives/fulldisclosure/2006-07/0467.html

Apache Tomcat can be forced to reveal a complete directory listing for any
directory by requesting a mapped file extension prepended with a semicolon, a
reserved character. The file does not need to exist.

Comment 4 Marcel Holtmann 2006-08-18 20:22:31 UTC
Check bug 201915 for additional information.



Note You need to log in before you can comment on or make changes to this bug.