Back

MEDIUM

httpd information disclosure in FileEtag

Published Oct 20, 2007

Description

Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child process IDs (PID).

Affected products

Remediation

Red Hat statement

Red Hat does not consider this to be a security issue. The information returned poses no threat to the target machine running httpd.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 20, 2007
Updated Aug 8, 2024
Reserved Oct 19, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Feb 25, 2003