Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 240680 - www-servers/apache disable TRACE
Summary: www-servers/apache disable TRACE
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Server (show other bugs)
Hardware: All Linux
: High normal
Assignee: Apache Team - Bugzilla Reports
URL: http://www.cgisecurity.com/whitehat-m...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2008-10-09 12:09 UTC by Julian Golderer
Modified: 2008-10-25 14:44 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Julian Golderer 2008-10-09 12:09:34 UTC
For security reasons (see linked pdf) the HTTP command TRACE may should be disabled by default.

TraceEnable off

Reproducible: Always
Comment 1 Benedikt Böhm (RETIRED) gentoo-dev 2008-10-25 14:44:06 UTC
fixed in 2.2.10, thanks