PT-2014-2140 · Apache+2 · Apache Http Server+2
Ansgar Burchardt
·
Publicado
2014-03-20
·
Atualizado
2014-03-27
·
CVE-2011-3196
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Domain Technologie Control (DTC) versions prior to 0.34.1
Description
The setup script in DTC uses world-readable permissions for the /etc/apache2/apache2.conf file, allowing local users to obtain the dtcdaemons MySQL password by reading the file.
Recommendations
For versions prior to 0.34.1, update to version 0.34.1 or later to resolve the issue. As a temporary workaround, consider changing the permissions of the /etc/apache2/apache2.conf file to restrict access until a patch is applied.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Http Server
Domain Technologie Control
Mysql Server