WEB_MISC rpm_query access

 

Code: p1321

Severity: Warning

 

Description: This event is generated when an attempt is made to gain information on installed packages on OpenLINUX.

Impact: This is a serious information leak, since an attack could then attempt to determine and exploit any vulnerable packages.

Corrective: Remove the package (/home/httpd/cgi-bin/rpm_query) Upgrade to the latest version of OpenLinux (2.3-17 or later),