[UNIX] Webmin view_man.cgi Security Vulnerability
From: support@securiteam.comDate: 12/25/01
- Previous message: support@securiteam.com: "[NEWS] Buffer Overflow Vulnerability in Oracle's "Unbreakable" 9iAS"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Date: Tue, 25 Dec 2001 07:53:01 +0100 (CET)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
Webmin view_man.cgi Security Vulnerability
------------------------------------------------------------------------
SUMMARY
<http://www.webmin.com/webmin/> Webmin is a user administration tool
written by Jamie Cameron in Perl that is designed to be lightweight,
functional, and easily extensible. A security vulnerability in the product
allows remote attackers to execute arbitrary code by manipulating a user
provided information field.
DETAILS
Vulnerable systems:
Webmin version 0.91 and prior
Webmin's view_man.cgi does not do any input checking allowing commands to
be executed by using a special string inside a normal request. By default,
the server runs as root, allowing an attacker to execute commands as root.
Example:
By including inside such a URL as:
http://photon:10000/man/view_man.cgi?page=ipcs&sec=8&opts=&for=rm
A command, an attacker can cause the viewing of the man files to do other
things besides viewing of the man files, such as execution of arbitrary
commands.
Solution:
An update for the view_man module has been released, for more information
please see:
<http://www.webmin.com/webmin/updates.html>
http://www.webmin.com/webmin/updates.html
ADDITIONAL INFORMATION
The information has been provided by Gobbles.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: support@securiteam.com: "[NEWS] Buffer Overflow Vulnerability in Oracle's "Unbreakable" 9iAS"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|