PT-2005-4652 · Usermin+1 · Usermin+2

Jack Louis

·

Publicado

2005-11-30

·

Atualizado

2019-04-03

·

CVE-2005-3912

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Webmin versions prior to 1.250 Usermin versions prior to 1.180
Description A format string issue in the miniserv.pl Perl web server allows remote attackers to cause a denial of service or possibly execute arbitrary code via format string specifiers in the username parameter to the login form, which is used in a syslog call.
Recommendations For Webmin versions prior to 1.250, update to version 1.250 or later to resolve the issue. For Usermin versions prior to 1.180, update to version 1.180 or later to resolve the issue. As a temporary workaround, consider disabling syslog logging in miniserv.pl until a patch is available. Restrict access to the login form to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3912
DSA-1199-1

Produtos afetados

Usermin
Webmin
Miniserv.Pl