|
Webmin "miniserv.pl" Perl Format String Vulnerability
|
|
|
|
|
Secunia Advisory:
|
SA17749
|
|
|
Release Date:
|
2005-11-29
|
|
Last Update:
|
2005-12-22
|
|
|
Critical:
|

Highly critical
|
|
Impact:
|
DoS System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Webmin 1.x
|
| | CVE reference: | CVE-2005-3912 (Secunia mirror)
|
|
|
Want to know the next time vulnerabilities are fixed in this product? - Companies can be alerted via email and SMS! |
|
|
Description: Jack Louis has discovered a vulnerability in Webmin, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a vulnerable system.
The vulnerability is caused due to a format string error in the "miniserv.pl" script when logging failed authentication attempts. This can be exploited to consume a large amount of CPU and memory resources on a vulnerable system by attempting to login with a specially crafted username.
It has also been reported that the vulnerability can be exploited in conjunction with a vulnerability in Perl for arbitrary code execution. However, this has not been shown.
For more information:
SA17802
The vulnerability has been confirmed in version 1.240. Other versions may also be affected.
Solution: Update to version 1.250.
http://www.webmin.com/
Provided and/or discovered by: Jack Louis, Dyad Security
Changelog: 2005-11-30: Updated "Solution" section.
2005-12-05: Added CVE reference.
2005-12-22: Updated "Name", "Critical" and "Description" sections.
Original Advisory: http://www.dyadsecurity.com/webmin-0001.html
Other References: SA17802:
http://secunia.com/advisories/17802/
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
11 Related Secunia Security Advisories, displaying 10
|
|
|
1. Webmin / Usermin "search" Cross-Site Scripting
|
|
2. Webmin Unspecified Command Execution Vulnerability
|
|
3. Webmin / Usermin "pam_login.cgi" Cross-Site Scripting
|
|
4. Webmin / Usermin chooser.cgi Script Insertion Vulnerability
|
|
5. Webmin / Usermin Cross-Site Scripting and Source Code Disclosure
|
|
6. Webmin / Usermin Arbitrary File Disclosure Vulnerability
|
|
7. Webmin Directory Traversal Vulnerability
|
|
8. Webmin / Usermin PAM Authentication Bypass Vulnerability
|
|
9. Usermin Shell Command Injection and Insecure Installation Vulnerabilities
|
|
10. Webmin / Usermin Security Restriction Bypass Vulnerabilities
|
Show all related advisories
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|