Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia: 2019-0237 Moderate: Webmin Remote Exploit Risk Fixed

mageia
Calendar Grey August 31, 2019
Dist Mageia Esm H88
The latest patches for Webmin tackle a security flaw that might allow remote exploitation on Mageia platforms.
Updated webmin package fixes security vulnerability: Webmin before 1.930 allows remote exploits if the option to change expired passwords is enabled (CVE-2019-15107)

Summary

Updated webmin package fixes security vulnerability:
Webmin before 1.930 allows remote exploits if the option to change expired passwords is enabled (CVE-2019-15107).
Note that it is only vulnerable if changing of expired passwords is enabled, which is not the case by default.

References

- https://bugs.mageia.org/show_bug.cgi?id=25331

- https://webmin.com/security/

- https://webmin.com/tags/webmin-changelog/

- https://www.cve.org/CVERecord?id=CVE-2019-15107

Resolution

SRPMS

- 7/core/webmin-1.930-1.mga7

Publication date: 31 Aug 2019
URL: https://advisories.mageia.org/MGASA-2019-0237.html
Type: security
CVE: CVE-2019-15107

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here