Mandrake Linux Security Advisory : webmin (MDKSA-2002:033)

high Nessus Plugin ID 13939

Synopsis

The remote Mandrake Linux host is missing one or more security updates.

Description

A vulnerability exists in all versions of Webmin prior to 0.970 that allows a remote attacker to login to Webmin as any user. All users of Webmin are encouraged to upgrade immediately.

Users of Mandrake Linux 8.0 and earlier will need to install some additional perl modules for this new version of webmin to work correctly.

Solution

Update the affected perl-Authen-PAM, perl-Net_SSLeay and / or webmin packages.

See Also

http://www.geocrawler.com/lists/3/SourceForge/12082/0/8595354/

Plugin Details

Severity: High

ID: 13939

File Name: mandrake_MDKSA-2002-033.nasl

Version: 1.16

Type: local

Published: 7/31/2004

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.3

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:perl-authen-pam, p-cpe:/a:mandriva:linux:perl-net_ssleay, p-cpe:/a:mandriva:linux:webmin, cpe:/o:mandrakesoft:mandrake_linux:7.1, cpe:/o:mandrakesoft:mandrake_linux:7.2, cpe:/o:mandrakesoft:mandrake_linux:8.0, cpe:/o:mandrakesoft:mandrake_linux:8.1, cpe:/o:mandrakesoft:mandrake_linux:8.2

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 5/21/2002

Reference Information

CVE: CVE-2002-0757

MDKSA: 2002:033