Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Webmin/Usermin Session ID Spoofing Unauthenticated Access Vulnerability

Solution:
It is recommended that all Gentoo Linux users who are running
app-admin/webmin upgrade to webmin-1.070 as follows:

emerge sync
emerge -u webmin
emerge clean

Gentoo Linux have recommended users who are running app-admin/usermin upgrade to usermin-1.000 as follows:

emerge sync
emerge -u usermin
emerge clean

EnGarde Secure Linux has released an advisory and fixes for the Digitial Guardian Webtool. Users are advise to upgrade as soon as possible.

HP has made fixes for available. See referenced advisory HPSBUX0303-250 for additional details.

SGI IRIX 6.5.x releases include the websetup package, which includes vulnerable versions of Webmin. websetup versions prior to 3.5 are prone to this issue. An updated version of websetup is available with the IRIX 6.5.20 Applications CD. Users are advised to upgrade to IRIX 6.5.20 or download a patched version of websetup from SGI.

Debian has released a security advisory (DSA 319-1) containing fixes to address this issue. Further information on how to obtain and apply fixes can be found in the attached advisory.

SCO has released an advisory (CSSA-2003-035.0) for OpenLinux that includes updates to address this issue.

The vendor has released updates which address this issue:


Webmin Usermin 0.4

Webmin Usermin 0.5

Webmin Usermin 0.6

Webmin Usermin 0.7

Webmin Usermin 0.8

Webmin Usermin 0.9

Webmin Usermin 0.91

Webmin Usermin 0.92

Webmin Usermin 0.93

Webmin Usermin 0.94

Webmin Usermin 0.95

Webmin Usermin 0.96

Webmin Usermin 0.97

Webmin Webmin 0.970

Webmin Usermin 0.98

Webmin Usermin 0.99

Webmin Webmin 1.0 50

Webmin Webmin 1.0 60

EnGarde Guardian Digital WebTool 1.2

HP Apache-Based Web Server 1.3.27 .00

SCO OpenLinux Workstation 3.1.1

SCO OpenLinux Server 3.1.1

SGI IRIX 6.5

SGI IRIX 6.5.1

SGI IRIX 6.5.10

SGI IRIX 6.5.11

SGI IRIX 6.5.12

SGI IRIX 6.5.13

SGI IRIX 6.5.14

SGI IRIX 6.5.15

SGI IRIX 6.5.16

SGI IRIX 6.5.17

SGI IRIX 6.5.18

SGI IRIX 6.5.19

SGI IRIX 6.5.2

SGI IRIX 6.5.3

SGI IRIX 6.5.4

SGI IRIX 6.5.5

SGI IRIX 6.5.6

SGI IRIX 6.5.7

SGI IRIX 6.5.8

SGI IRIX 6.5.9







 

Privacy Statement
Copyright 2008, SecurityFocus