Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 7 articles for you...
203

Mageia 8 MGASA-2022-0216 Moderate: Webmin User Privilege Escalation

Less privileged Webmin users (excluding those created by Virtualmin and Cloudmin) can modify arbitrary files with root privileges, and so run commands as root (CVE-2022-30708). References: . MGASA-2022-0216 - Updated webmin packages fix security vulnerability Publication date: 03 Jun 2022 URL: https://advisories.mageia.org/MGASA-2022-0216.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-30708 Less privileged Webmin users (excluding those created by Virtualmin and Cloudmin) can modify arbitrary files with root privileges, and so run commands as root (CVE-2022-30708). References: - https://bugs.mageia.org/show_bug.cgi?id=30465 - https://webmin.com/security/ - https://webmin.com/tags/webmin-changelog/ - https://www.cve.org/CVERecord?id=CVE-2022-30708 SRPMS: - 8/core/webmin-1.994-1.mga8 . MGASA-2022-0217: New versions of Webmin for Mageia resolve a severe security vulnerability that permitted unauthorized root file access.. Mageia Webmin Security Fix, User Privilege Escalation, Webmin Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 03, 2022 Important Mageia
203

Mageia: 2021-0344 Moderate: Webmin Input Handling Issue

The webmin package has been updated to version 1.979, which has fixes for handling un-trusted inputs in the Network Configuration module. Also, the openvpn module has been updated to version 3.2. . MGASA-2021-0344 - Updated webmin package fixes security vulnerability Publication date: 12 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0344.html Type: security Affected Mageia releases: 7, 8 The webmin package has been updated to version 1.979, which has fixes for handling un-trusted inputs in the Network Configuration module. Also, the openvpn module has been updated to version 3.2. References: - https://bugs.mageia.org/show_bug.cgi?id=29137 - https://webmin.com/tags/webmin-changelog/ - ;catid=7 SRPMS: - 7/core/webmin-1.979-1.1.mga7 - 8/core/webmin-1.979-1.1.mga8 . Explore the details of Mageia 2021-0344: the recent webmin security patch enhancing network settings and optimizing openvpn performance.. webmin update,Mageia security,network configuration,openvpn module. . LinuxSecurity.com Team

Calendar 2 Jul 12, 2021 Mageia
89

Fedora 34: 2021-7ac1821d1f Critical: SQL Injection In Webmin Advisory

Update to 1.2.6.2 (#1906752). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-6cc5654c0e 2020-12-21 01:31:12.651546 --------------------------------------------------------------------------------Name : phpldapadmin Product : Fedora 33 Version : 1.2.6.2 Release : 1.fc33 URL : https://sourceforge.net/projects/phpldapadmin/ Summary : Web-based tool for managing LDAP servers Description : PhpLDAPadmin is a web-based LDAP client. It provides easy, anywhere-accessible, multi-language administration for your LDAP server. Its hierarchical tree-viewer and advanced search functionality make it intuitive to browse and administer your LDAP directory. Since it is a web application, this LDAP browser works on many platforms, making your LDAP server easily manageable from any location. PhpLDAPadmin is the perfect LDAP browser for the LDAP professional and novice alike. Its user base consists mostly of LDAP administration professionals. Edit /etc/phpldapadmin/config.php to change default (localhost) LDAP server location and other things. Edit /etc/httpd/conf.d/phpldapadmin.conf to allow access by remote web-clients. --------------------------------------------------------------------------------Update Information: Update to 1.2.6.2 (#1906752) --------------------------------------------------------------------------------ChangeLog: * Fri Dec 11 2020 Dmitry Butskoy - 1.2.6.2-1 - Update to 1.2.6.2 (#1906752) --------------------------------------------------------------------------------References: [ 1 ] Bug #1906752 - CVE-2020-35132 phpldapadmin: allows users to store malicious values which could result in XSS via get_request in lib/function.php https://bugzilla.redhat.com/show_bug.cgi?id=1906752 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2020-6cc5654c0e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Fedora 33 has launched a new version of phpldapadmin addressing security vulnerabilities related to XSS, aimed at improving the administration of LDAP servers.. Fedora Update, XSS Vulnerability, phpldapadmin Tool. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 20, 2020 Critical Fedora
203

Mageia 7: MGASA-2020-0400 Moderate: Webmin XSS and Input Issues

An XSS Vulnerability exists in Webmin 1.941 and earlier affecting the Cluster Shell Commands Endpoint. A user may enter any XSS Payload into the Command field and execute it. Then, after revisiting the Cluster Shell Commands Menu, the XSS Payload will be rendered and executed. (CVE-2020-8820) . MGASA-2020-0400 - Updated webmin package fixes security vulnerabilities Publication date: 08 Nov 2020 URL: https://advisories.mageia.org/MGASA-2020-0400.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-8820, CVE-2020-8821, CVE-2020-12670 An XSS Vulnerability exists in Webmin 1.941 and earlier affecting the Cluster Shell Commands Endpoint. A user may enter any XSS Payload into the Command field and execute it. Then, after revisiting the Cluster Shell Commands Menu, the XSS Payload will be rendered and executed. (CVE-2020-8820) An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint. A user may enter HTML code into the Command field and submit it. Then, after visiting the Action Logs Menu and displaying logs, the HTML code will be rendered (however, JavaScript is not executed). Changes are kept across users. (CVE-2020-8821) XSS exists in Webmin 1.941 and earlier affecting the Save function of the Read User Email Module / mailboxes Endpoint when attempting to save HTML emails. This module parses any output without sanitizing SCRIPT elements, as opposed to the View function, which sanitizes the input correctly. A malicious user can send any JavaScript payload into the message body and execute it if the user decides to save that email. (CVE-2020-12670) References: - https://bugs.mageia.org/show_bug.cgi?id=27459 - https://webmin.com/security/ - https://webmin.com/tags/webmin-changelog/ - https://www.cve.org/CVERecord?id=CVE-2020-8820 - https://www.cve.org/CVERecord?id=CVE-2020-8821 - https://www.cve.org/CVERecord?id=CVE-2020-12670 SRPMS: - 7/core/webmin-1.960-1.mga7 . MGASA-2020-0500 highlights vulnerabilities in Webminconcerning XSS and deficient input validation on Mageia 8 version. Urgent update suggested!. XSS Exploits, Webmin Security, Mageia Update, Command Shell Vulnerability. . LinuxSecurity.com Team

Calendar 2 Nov 08, 2020 Mageia
203

Mageia: 2019-0237 Moderate: Webmin Remote Exploit Risk Fixed

Updated webmin package fixes security vulnerability: Webmin before 1.930 allows remote exploits if the option to change expired passwords is enabled (CVE-2019-15107). . MGASA-2019-0237 - Updated webmin packages fix security vulnerability Publication date: 31 Aug 2019 URL: https://advisories.mageia.org/MGASA-2019-0237.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-15107 Updated webmin package fixes security vulnerability: Webmin before 1.930 allows remote exploits if the option to change expired passwords is enabled (CVE-2019-15107). Note that it is only vulnerable if changing of expired passwords is enabled, which is not the case by default. References: - https://bugs.mageia.org/show_bug.cgi?id=25331 - https://webmin.com/security/ - https://webmin.com/tags/webmin-changelog/ - https://www.cve.org/CVERecord?id=CVE-2019-15107 SRPMS: - 7/core/webmin-1.930-1.mga7 . The latest patches for Webmin tackle a security flaw that might allow remote exploitation on Mageia platforms.. Webmin Security, Mageia Update, Remote Exploit Fix. . LinuxSecurity.com Team

Calendar 2 Aug 31, 2019 Mageia
91

Gentoo: GLSA-200707-05 Low Severity: Webmin, Usermin XSS Threat

Webmin and Usermin are vulnerable to cross-site scripting vulnerabilities (XSS).. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200707-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: Webmin, Usermin: Cross-site scripting vulnerabilities Date: July 05, 2007 Bugs: #181385 ID: 200707-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Webmin and Usermin are vulnerable to cross-site scripting vulnerabilities (XSS). Background ========= Webmin is a web-based administrative interface for Unix-like systems. Usermin is a simplified version of Webmin designed for use by normal users rather than system administrators. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-admin/webmin < 1.350 > = 1.350 2 app-admin/usermin < 1.280 > = 1.280 ------------------------------------------------------------------- 2 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== The pam_login.cgi file does not properly sanitize user input before sending it back as output to the user. Impact ===== An unauthenticated attacker could entice a user to browse a specially crafted URL, allowing for the execution of script code in the context of the user's browser and for the theft of browser credentials. This may permit the attacker to login to Webmin or Usermin with the user's permissions. Workaround ========= There is noknown workaround at this time. Resolution ========= All Webmin users should update to the latest stable version: # emerge --sync # emerge --ask --verbose --oneshot "> =app-admin/webmin-1.350" All Usermin users should update to the latest stable version: # emerge --sync # emerge --ask --verbose --oneshot "> =app-admin/usermin-1.280" References ========= [ 1 ] CVE-2007-3156 https://www.cve.org/CVERecord?id=CVE-2007-3156 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200707-05 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2007 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Webmin and Usermin have low severity XSS vulnerabilities, exposing user credentials. Update to the latest versions promptly.. Webmin Update, Usermin Advisory, Gentoo Security, XSS Threats. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Jul 06, 2007 Low Gentoo
87

Debian 3.1: DSA-1199-1 Critical: Webmin Input Vulnerabilities

Updated package.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1199-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Noah Meyerhans October 23, 2006 - ------------------------------------------------------------------------Package : webmin Vulnerability : multiple Problem type : remote Debian-specific: no CVE Id(s) : CVE-2005-3912 CVE-2006-3392 CVE-2006-4542 BugTraq ID : 15629 18744 19820 Debian Bug : 341394 381537 391284 Several vulnerabilities have been identified in webmin, a web-based administration toolkit. CVE-2005-3912 A format string vulnerability in miniserv.pl could allow an attacker to cause a denial of service by crashing the application or exhausting system resources, and could potentially allow arbitrary code execution. CVE-2006-3392 Improper input sanitization in miniserv.pl could allow an attacker to read arbitrary files on the webmin host by providing a specially crafted URL path to the miniserv http server. CVE-2006-4542 Improper handling of null characters in URLs in miniserv.pl could allow an attacker to conduct cross-site scripting attacks, read CGI program source code, list local directories, and potentially execute arbirary code. For the stable distribution (sarge), these problems have been fixed in version 1.180-3sarge1 Webmin is not included in unstable (sid) or testing (etch), so these problems are not present. We recommend that you upgrade your webmin (1.180-3sarge1) package. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources fromthe footer to the proper configuration. Debian 3.1 (stable) - -------------------Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, m68k, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 703 5e723deaccb3db60794e0cb385666992 Size/MD5 checksum: 2261496 ff19d5500955302455e517cb2942c9d0 Size/MD5 checksum: 31458 f8fe363e7ccd8fe4072d84cd86a3510e Architecture independent packages: Size/MD5 checksum: 1121200 8fa7064325ded44e7f8dbd226b81d9dd Size/MD5 checksum: 1097552 34d96210d581dde8ffea7be82e0897f4 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Essential enhancements to input validation in the Debian webmin package effectively mitigate potential remote exploitation risks.. Debian Security, Webmin Update, Input Validation, Remote Attack, System Administration. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 23, 2006 Critical Debian
91

Gentoo: GLSA-200512-02 High: Webmin, Usermin Format String Exploit

Webmin and Usermin are vulnerable to a format string vulnerability which may lead to the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200512-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Webmin, Usermin: Format string vulnerability Date: December 07, 2005 Bugs: #113888 ID: 200512-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Webmin and Usermin are vulnerable to a format string vulnerability which may lead to the execution of arbitrary code. Background ========= Webmin is a web-based interface for Unix-like systems. Usermin is a simplified version of Webmin designed for use by normal users rather than system administrators. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-admin/webmin < 1.250 > = 1.250 2 app-admin/usermin < 1.180 > = 1.180 ------------------------------------------------------------------- 2 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== Jack Louis discovered that the Webmin and Usermin "miniserv.pl" web server component is vulnerable to a Perl format string vulnerability. Login with the supplied username is logged via the Perl "syslog" facility in an unsafe manner. Impact ===== A remote attacker can trigger this vulnerability via a specially crafted username containing format string data. This can be exploited to consumea large amount of CPU and memory resources on a vulnerable system, and possibly to execute arbitrary code of the attacker's choice with the permissions of the user running Webmin. Workaround ========= There is no known workaround at this time. Resolution ========= All Webmin users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-admin/webmin-1.250" All Usermin users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-admin/usermin-1.180" References ========= [ 1 ] CVE-2005-3912 [ 2 ] Dyad Security Advisory Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200512-02 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . Alert: Webmin and Usermin on Gentoo have a critical format string vulnerability that allows for potential arbitrary code execution. Immediate updates are essential. Webmin Security, Usermin Threat, Gentoo Advisory, Format String Issue, High Risk Software. . LinuxSecurity.com Team

Calendar 2 Dec 07, 2005 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here