One vulnerability allows a malicious user to read passwords and discern network structure while the other allows a malicious user to create or browse file directories on a Web server. Both vulnerabilities provide a malicious user with access to sensitive data on a Web server running Apache 1.3.9 (Apache 1.3.12 in SuSE 6.4). Apache is the default Web server in SuSE Linux.