SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Welcome to SecurityTracker!
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  Application (Generic)  >  Webmin Vendors:  Cameron, Jamie
Webmin Discloses Module Configuration Data to Remote Authenticated Users
SecurityTracker Alert ID:  1010422
SecurityTracker URL:  http://securitytracker.com/id?1010422
CVE Reference:  CAN-2004-0582   (Links to External Site)
Updated:  Jun 24 2004
Original Entry Date:  Jun 8 2004
Impact:  Denial of service via network, Disclosure of system information, Disclosure of user information
Fix Available:  Yes   Vendor Confirmed:  Yes  
Version(s): 1.140 and prior versions
Description:  Two vulnerabilities were reported in Webmin. A remote user can cause user accounts to be locked out. A remote authenticated user can view module configuration data.

The vendor reported that a remote authenticated user can view the configuration of arbitrary modules, even if the user should not have access to the module.

It is also reported that a remote user can send an invalid username or password to lock out valid users.

Impact:  A remote authenticated user can view the configuration of arbitrary modules on the system.

A remote user can lock out a valid user's account.

Solution:  The vendor has issued a fixed version (1.150), available at:

http://www.webmin.com/

Vendor URL:  www.webmin.com/changes-1.150.html (Links to External Site)
Cause:  Access control error, State error
Underlying OS:  Linux (Any), UNIX (Any)

Message History:   This archive entry has one or more follow-up message(s) listed below.
Jun 11 2004 (SNS Issues Advisory) Webmin Discloses Module Configuration Data to Remote Authenticated Users   (snsadv@lac.co.jp (snsadv))
SecureNet Service has issued their advisory.
Jun 17 2004 (Gentoo Issues Fix) Webmin Discloses Module Configuration Data to Remote Authenticated Users   (Kurt Lieber <klieber@gentoo.org>)
Gentoo has released a fix.
Jul 6 2004 (Debian Issues Fix) Webmin Discloses Module Configuration Data to Remote Authenticated Users   (Matt Zimmerman <mdz@debian.org>)
Debian has released a fix.
Jul 17 2004 (Conectiva Issues Fix) Webmin Discloses Module Configuration Data to Remote Authenticated Users   (Conectiva Updates <secure@conectiva.com.br>)
Conectiva has released a fix.
Jul 28 2004 (Mandrake Issues Fix) Webmin Discloses Module Configuration Data to Remote Authenticated Users   (Mandrake Linux Security Team <security@linux-mandrake.com>)
Mandrake has issued a fix.



 Source Message Contents

Date:  Mon, 07 Jun 2004 15:19:56 -0400
Subject:  http://www.webmin.com/changes-1.150.html

 

http://www.webmin.com/changes-1.150.html

 > Changes since Webmin version 1.140
 >
 > Webmin Core
 >     Fixed a security hole that allowed any user to view the configuration of any module,
 >     even those that they should not have access to.
 >     Fixed a security hole that could allow an attacker to lock valid users by sending a
 >     bogus username or password.


 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2004, SecurityGlobal.net LLC