MGASA-2019-0237 - Updated webmin packages fix security vulnerability

Publication date: 31 Aug 2019
URL: https://advisories.mageia.org/MGASA-2019-0237.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2019-15107

Updated webmin package fixes security vulnerability:

Webmin before 1.930 allows remote exploits if the option to change expired
passwords is enabled (CVE-2019-15107).

Note that it is only vulnerable if changing of expired passwords is enabled,
which is not the case by default.

References:
- https://bugs.mageia.org/show_bug.cgi?id=25331
- https://webmin.com/security/
- https://webmin.com/tags/webmin-changelog/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15107

SRPMS:
- 7/core/webmin-1.930-1.mga7

Mageia 2019-0237: webmin security update

Updated webmin package fixes security vulnerability: Webmin before 1.930 allows remote exploits if the option to change expired passwords is enabled (CVE-2019-15107)

Summary

Updated webmin package fixes security vulnerability:
Webmin before 1.930 allows remote exploits if the option to change expired passwords is enabled (CVE-2019-15107).
Note that it is only vulnerable if changing of expired passwords is enabled, which is not the case by default.

References

- https://bugs.mageia.org/show_bug.cgi?id=25331

- https://webmin.com/security/

- https://webmin.com/tags/webmin-changelog/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15107

Resolution

MGASA-2019-0237 - Updated webmin packages fix security vulnerability

SRPMS

- 7/core/webmin-1.930-1.mga7

Severity
Publication date: 31 Aug 2019
URL: https://advisories.mageia.org/MGASA-2019-0237.html
Type: security
CVE: CVE-2019-15107

Related News