PT-2005-4652 · Usermin+1 · Usermin+2

Jack Louis

·

Published

2005-11-30

·

Updated

2019-04-03

·

CVE-2005-3912

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Webmin versions prior to 1.250 Usermin versions prior to 1.180
Description A format string issue in the miniserv.pl Perl web server allows remote attackers to cause a denial of service or possibly execute arbitrary code via format string specifiers in the username parameter to the login form, which is used in a syslog call.
Recommendations For Webmin versions prior to 1.250, update to version 1.250 or later to resolve the issue. For Usermin versions prior to 1.180, update to version 1.180 or later to resolve the issue. As a temporary workaround, consider disabling syslog logging in miniserv.pl until a patch is available. Restrict access to the login form to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3912
DSA-1199-1

Affected Products

Usermin
Webmin
Miniserv.Pl