Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Gentoo: 202304-09 Severe: Webmin Unauthenticated Access Threat

gentoo
Calendar Grey February 22, 2003
Dist Gentoo Esm H88
Important alert for Gentoo enthusiasts: a critical vulnerability in webmin has been identified requiring an immediate update to version 1.070 to ensure safety.
Due to a remotely exploitable security hole being discovered thateffects all previous Webmin releases, version 1.070 is now availablefor download

Summary


- ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200302-12
- ---------------------------------------------------------------------
    FIXED VERSION : 1.070

- ---------------------------------------------------------------------
From announcement:
"Due to a remotely exploitable security hole being discovered that effects all previous Webmin releases, version 1.070 is now available for download from Webmin and mirror sites. This problem was reported by Cintia M. Imanishi, but fortunately there have been no known malicious exploits of it yet. However, all usersshould upgrade to 1.070 as soon as possible."
Read the full announcement at: http://marc.theaimsgroup.com/?l=webmin-announce&m=104587858408101&w=2
SOLUTION
It is recommended that all Gentoo Linux users who are running app-admin/webmin upgrade to webmin-1.070 as follows:
emerge sync emerge -u webmin emerge clean
...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : webmin
SUMMARY : unauthorized access
DATE : 2003-02-22 18:48 UTC
EXPLOIT : remote
VERSIONS AFFECTED : <=1.060

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here