|
|
Subscribe / Log in / New account

webmin, usermin: remote code execution through PAM authentication

Package(s):webmin usermin CVE #(s):CAN-2005-3042
Created:September 26, 2005 Updated:October 7, 2005
Description: Keigo Yamazaki discovered that the miniserv.pl webserver, used in both Webmin and Usermin, does not properly validate authentication credentials before sending them to the PAM (Pluggable Authentication Modules) authentication process. The default configuration shipped with Gentoo does not enable the "full PAM conversations" option and is therefore unaffected by this flaw.
Alerts:
Mandriva MDKSA-2005:176 webmin 2005-10-07
Gentoo 200509-17 webmin 2005-09-24

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds