HTTP: Caldera Linux rpm_query Disclosure
This signature detects requests for the rpm_query CGI script used in Caldera OpenLinux 2.3. Attackers can obtain a list of names and versions of packages installed on the system.
Extended Description
A vulnerability exists in the default installation of Caldera OpenLinux 2.3. A CGI is installed in /home/httpd/cgi-bin/ names rpm_query. Any user can run this CGI and obtain a listing of the packages, and versions of packages, installed on this system. This could be used to determine vulnerabilities on the machine remotely.
Affected Products
Caldera openlinux
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Caldera
5.0