PT-2005-4652 · Usermin+1 · Usermin+2
Jack Louis
·
Published
2005-11-30
·
Updated
2019-04-03
·
CVE-2005-3912
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Webmin versions prior to 1.250
Usermin versions prior to 1.180
Description
A format string issue in the miniserv.pl Perl web server allows remote attackers to cause a denial of service or possibly execute arbitrary code via format string specifiers in the
username parameter to the login form, which is used in a syslog call.Recommendations
For Webmin versions prior to 1.250, update to version 1.250 or later to resolve the issue.
For Usermin versions prior to 1.180, update to version 1.180 or later to resolve the issue.
As a temporary workaround, consider disabling syslog logging in miniserv.pl until a patch is available.
Restrict access to the login form to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Usermin
Webmin
Miniserv.Pl