/doc/ shows entire /usr/share/doc, not apache doc

Bug #551617 reported by jan meeuwissen
262
This bug affects 1 person
Affects Status Importance Assigned to Milestone
apache2 (Ubuntu)
Invalid
Medium
Unassigned
Karmic
Invalid
Undecided
Unassigned
Lucid
Invalid
Medium
Unassigned

Bug Description

Binary package hint: apache2

after installing apache2, but not apache2-doc:
http://localhost/doc/
shows the entire directory listing for /usr/share/doc/
therefore revealing what packages are installed.

ProblemType: Bug
Architecture: i386
Date: Tue Mar 30 11:26:04 2010
DistroRelease: Ubuntu 9.10
LiveMediaBuild: Ubuntu 9.10 "Karmic Koala" - Release i386 (20091028.5)
Package: apache2 2.2.12-1ubuntu2.2
PackageArchitecture: all
ProcEnviron:
 LANG=en_US.UTF-8
 SHELL=/bin/bash
ProcVersionSignature: Ubuntu 2.6.31-14.48-generic
SourcePackage: apache2
Uname: Linux 2.6.31-14-generic i686

Revision history for this message
jan meeuwissen (j-meeuwissen) wrote :
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

I can confirm this on Lucid.

security vulnerability: yes → no
visibility: private → public
tags: added: karmic
security vulnerability: no → yes
Changed in apache2 (Ubuntu):
status: New → Confirmed
importance: Undecided → Medium
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Thanks for reporting this.

The apache2 config file has the following:

Allow from 127.0.0.0/255.0.0.0 ::1/128

So, it's not a security issue. Closing the bug.

Changed in apache2 (Ubuntu Karmic):
status: New → Invalid
Changed in apache2 (Ubuntu Lucid):
status: Confirmed → Invalid
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.