TUCoPS :: Linux :: Debian :: dsa-319.htm

webmin - session ID spoofing

Debian Security Advisory

DSA-319-1 webmin -- session ID spoofing

Date Reported:
12 Jun 2003
Affected Packages:
webmin
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CAN-2003-0101.
More information:

miniserv.pl in the webmin package does not properly handle metacharacters, such as line feeds and carriage returns, in Base64-encoded strings used in Basic authentication. This vulnerability allows remote attackers to spoof a session ID, and thereby gain root privileges.

For the stable distribution (woody) this problem has been fixed in version 0.94-7woody1.

The old stable distribution (potato) does not contain a webmin package.

For the unstable distribution (sid) this problem is fixed in version 1.070-1.

We recommend that you update your webmin package.

Fixed in:

Debian GNU/Linux 3.0 (woody)

Source:
http://security.debian.org/pool/updates/main/w/webmin/webmin_0.94-7woody1.dsc
http://security.debian.org/pool/updates/main/w/webmin/webmin_0.94-7woody1.diff.gz
http://security.debian.org/pool/updates/main/w/webmin/webmin_0.94.orig.tar.gz
Architecture-independent component:
http://security.debian.org/pool/updates/main/w/webmin/webmin-apache_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-bind8_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-burner_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-cluster-software_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-cluster-useradmin_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-core_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-cpan_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-dhcpd_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-exports_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-fetchmail_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-heartbeat_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-inetd_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-jabber_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-lpadmin_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-mon_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-mysql_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-nis_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-postfix_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-postgresql_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-ppp_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-qmailadmin_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-quota_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-raid_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-samba_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-sendmail_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-software_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-squid_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-sshd_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-ssl_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-status_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-stunnel_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-wuftpd_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-xinetd_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin_0.94-7woody1_all.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/w/webmin/webmin-grub_0.94-7woody1_i386.deb

MD5 checksums of the listed files are available in the original advisory.


TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH