Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Gentoo Linux Security Advisory GLSA 200509-17
https://security.gentoo.org/
Severity: High
Title: Webmin, Usermin: Remote code execution through PAM
authentication
Date: September 24, 2005
Bugs: #106705
ID: 200509-17
Synopsis
=======
If Webmin or Usermin is configured to use full PAM conversations, it is
vulnerable to the remote execution of arbitrary code with root
privileges.
Background
=========
Webmin and Usermin are web-based system administration consoles. Webmin
allows an administrator to easily configure servers and other features.
Usermin allows users to configure their own accounts, execute commands,
and read e-mails.
...
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.