Webmin And Usermin Account Lockout Bypass Vulnerability
BID:10523
Info
Webmin And Usermin Account Lockout Bypass Vulnerability
| Bugtraq ID: | 10523 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0583 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 11 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Discovery of this issue is credited to Keigo Yamazaki. |
| Vulnerable: |
Webmin Webmin 1.140 Webmin Webmin 1.0 70 Usermin Usermin 1.0 70 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: |
Webmin Webmin 1.150 Usermin Usermin 1.0 80 |
Discussion
Webmin And Usermin Account Lockout Bypass Vulnerability
Webmin and Usermin are affected by an account lockout bypass vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input.
This issue may be leveraged to carry out brute force authentication attacks against the affected computer; facilitating unauthorized access to the Webmin and Usermin accounts as well as the affected computer. It has been reported that this issue can also be leveraged to prevent users from logging in, although how this occurs is unspecified.
Webmin and Usermin are affected by an account lockout bypass vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input.
This issue may be leveraged to carry out brute force authentication attacks against the affected computer; facilitating unauthorized access to the Webmin and Usermin accounts as well as the affected computer. It has been reported that this issue can also be leveraged to prevent users from logging in, although how this occurs is unspecified.
Exploit / POC
Webmin And Usermin Account Lockout Bypass Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Webmin And Usermin Account Lockout Bypass Vulnerability
Solution:
The vendor has released upgrades dealing with this issue.
Debian GNU/Linux has released advisory DSA 526-1 addressing this issue. Please see the referenced advisory for further information.
Mandrake Linux has released advisory MDKSA-2004:074 addressing this issue. Please see the referenced advisory for further information.
Turbolinux has released advisory 20050207 [TURBOLINUX SECURITY INFO] 07/Feb/2005 to address various issues. Please see the referenced advisory for more information.
Webmin Webmin 1.0 70
Usermin Usermin 1.0 70
Webmin Webmin 1.140
Solution:
The vendor has released upgrades dealing with this issue.
Debian GNU/Linux has released advisory DSA 526-1 addressing this issue. Please see the referenced advisory for further information.
Mandrake Linux has released advisory MDKSA-2004:074 addressing this issue. Please see the referenced advisory for further information.
Turbolinux has released advisory 20050207 [TURBOLINUX SECURITY INFO] 07/Feb/2005 to address various issues. Please see the referenced advisory for more information.
Webmin Webmin 1.0 70
-
Mandrake webmin-1.070-1.1.91mdk.noarch.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake webmin-1.070-1.1.91mdk.noarch.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Webmin webmin-1.150.tar.gz
http://prdownloads.sourceforge.net/webadmin/webmin-1.150.tar.gz
Usermin Usermin 1.0 70
-
Usermin usermin-1.080.tar.gz
http://www.webmin.com/udownload.html
Webmin Webmin 1.140
-
Webmin webmin-1.150.tar.gz
http://prdownloads.sourceforge.net/webadmin/webmin-1.150.tar.gz
References
Webmin And Usermin Account Lockout Bypass Vulnerability
References:
References: