First published: Sun Mar 05 2000(Updated: )
The default installation of Caldera OpenLinux 2.3 includes the CGI program rpm_query, which allows remote attackers to determine what packages are installed on the system.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SCO OpenLinux Server | =2.3 | |
=2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0192 is classified as a moderate severity vulnerability due to its ability to reveal installed packages to remote attackers.
To fix CVE-2000-0192, you should disable the rpm_query CGI script or upgrade to a patched version of Caldera OpenLinux.
The impact of CVE-2000-0192 is that it allows remote attackers to gather information about installed packages, which could assist in further attacks.
Yes, CVE-2000-0192 is exploitable from the internet, as it involves a default CGI script accessible via web servers.
CVE-2000-0192 specifically affects the default installation of Caldera OpenLinux version 2.3.