Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Gentoo: 200502-12 Normal: Webmin Root Password Exposed in Packages

gentoo
Calendar Grey February 11, 2005
Scroller Gentoo
The Gentoo GLSA 200502-13 report addresses a vulnerability concerning Webmin that inadvertently reveals hashed root passwords within certain binary distributions.
Portage-built Webmin binary packages accidentally include a file containing the local encrypted root password.

Summary

Gentoo Linux Security Advisory GLSA 200502-12 https://security.gentoo.org/ Severity: Normal Title: Webmin: Information leak in Gentoo binary package Date: February 11, 2005 Bugs: #77731 ID: 200502-12

Synopsis ======= Portage-built Webmin binary packages accidentally include a file containing the local encrypted root password.
Background ========= Webmin is a web-based system administration console allowing an administrator to easily configure servers and other features. Using the 'buildpkg' FEATURE, or the -b/-B emerge options, Portage can build reusable binary packages for any of the packages available through the Portage tree.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-admi...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
important
Lowest
Low
Medium
High
Critical

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround