CVE-2005-3042
Summary
| CVE | CVE-2005-3042 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-09-22 10:03:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when "full PAM conversations" is enabled, allows remote attackers to bypass authentication by spoofing session IDs via certain metacharacters (line feed or carriage return). |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Changes since Webmin version 1.220 | af854a3a-2127-422b-91ae-364da2661108 | www.webmin.com | Patch |
| Advisories - Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Neohapsis Archives - Bugtraq - #0257 - [SNS Advisory No.83] Webmin/Usermin PAM Authentication Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Patch, Vendor Advisory |
| Secunia - Advisories - SUSE Updates for Multiple Packages | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Webmin/Usermin PAM Authentication Bypass Vulnerability - SecurityReason.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Changes since Usermin version 1.150 | af854a3a-2127-422b-91ae-364da2661108 | www.webmin.com | |
| Secunia - Advisories - Webmin / Usermin PAM Authentication Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Gentoo Linux Documentation -- Webmin, Usermin: Remote code execution through PAM authentication | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| JVN#40940493: Webmin および Usermin における認証回避の脆弱性 | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| www.osvdb.org/19575 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| セキュリティ対策のラック|情報を守るセキュリティ対策のパイオニア | af854a3a-2127-422b-91ae-364da2661108 | www.lac.co.jp | Patch, Vendor Advisory |
| Webmin / Usermin Remote PAM Authentication Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| JVN:JVN#40940493 | MITRE | jvn.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.