CVE-2006-3392
Improper input sanitization in miniserv.pl could allow an
attacker to read arbitrary files on the webmin host by providing
a specially crafted URL path to the miniserv http server.
CVE-2006-4542
Improper handling of null characters in URLs in miniserv.pl
could allow an attacker to conduct cross-site scripting attacks,
read CGI program source code, list local directories, and
potentially execute arbirary code.
For the stable distribution (sarge), these problems have been fixed in
version 1.180-3sarge1
Webmin is not included in unstable (sid) or testing (etch), so these
problems are not present.
We recommend that you upgrade your webmin (1.180-3sarge1) package.
Upgrade instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given below:
apt-get update
will update the internal database
apt-...
Get the latest Linux and open source security news straight to your inbox.