Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Webmin / Usermin Installation Insecure Temporary File Creation Vulnerability

Solution:
It is reported that Usermin version 1.090 and Webmin 1.160 are not affected by this issue.

Gentoo has released an advisory to address these issues. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:

Usermin:
emerge sync
emerge -pv ">=app-admin/usermin-1.090"
emerge ">=app-admin/usermin-1.090"

Webmin:
emerge sync
emerge -pv ">=app-admin/webmin-1.160"
emerge ">=app-admin/webmin-1.160"

Debian has released advisory DSA 544-1 along with fixes dealing with this issue. Please see the referenced advisory for more information.

Mandrake Linux has released advisory MDKSA-2004:101 along with fixes to address this issue. Please see the referenced advisory for further information.

Turbolinux has released advisory 20050207 [TURBOLINUX SECURITY INFO] 07/Feb/2005 to address various issues. Please see the referenced advisory for more information.


Usermin Usermin 0.7

Usermin Usermin 0.80

Usermin Usermin 0.90

Usermin Usermin 0.910

Usermin Usermin 0.920

Usermin Usermin 0.930

Usermin Usermin 0.940

Usermin Usermin 0.950

Usermin Usermin 0.960

Usermin Usermin 0.970

Usermin Usermin 0.980

Usermin Usermin 0.990

Webmin Webmin 1.0 00

Webmin Webmin 1.0 90

Webmin Webmin 1.0 50

Webmin Webmin 1.0 80

Usermin Usermin 1.0 60

Webmin Webmin 1.0 70

Usermin Usermin 1.0 70

Usermin Usermin 1.0 20

Usermin Usermin 1.0 10

Usermin Usermin 1.0 00

Usermin Usermin 1.0 30

Usermin Usermin 1.0 80

Usermin Usermin 1.0 51

Usermin Usermin 1.0 40

Webmin Webmin 1.0 60

Webmin Webmin 1.0 20

Webmin Webmin 1.100

Webmin Webmin 1.110

Webmin Webmin 1.121

Webmin Webmin 1.130

Webmin Webmin 1.140

Webmin Webmin 1.150







 

Privacy Statement
Copyright 2008, SecurityFocus