PT-2005-1489 · Webmin · Webmin
Tavis Ormandy
·
Publicado
2005-02-15
·
Atualizado
2017-07-11
·
CVE-2005-0427
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Webmin versions prior to 1.170-r3
Description
The issue allows remote attackers to obtain the encrypted root password, which could potentially be cracked. This occurs because the ebuild of Webmin on Gentoo Linux includes the encrypted root password in the miniserv.users file when building a tbz2 of the webmin package.
Recommendations
For versions prior to 1.170-r3, update to version 1.170-r3 or later to resolve the issue. As a temporary workaround, consider restricting access to the miniserv.users file to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Webmin