Back

MEDIUM

Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server

Published Feb 2, 2002

Description

Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server.

Affected products

Remediation

Red Hat statement

Red Hat does not consider this flaw to be a security issue. If UserDir is enabled, you can configure httpd to respond with a custom error page and a single error code whether the user exists or not. The UserDir functionality is disabled by default in httpd on Red Hat Enterprise Linux 5, 6, and 7, and is thus not exposed on default installations.

Metrics

Weaknesses (0)

No CWE recorded.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 2, 2002
Updated Aug 8, 2024
Reserved Jan 31, 2002
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a