Webmin / Usermin Remote PAM Authentication Bypass Vulnerability
BID:14889
Info
Webmin / Usermin Remote PAM Authentication Bypass Vulnerability
| Bugtraq ID: | 14889 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3042 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 20 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Keigo Yamazaki (LAC) discovered this vulnerability. |
| Vulnerable: |
Webmin Webmin 1.220 Webmin Webmin 1.210 Webmin Webmin 1.200 Webmin Usermin 1.150 Webmin Usermin 1.140 Webmin Usermin 1.130 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 2.1 x86_64 MandrakeSoft Corporate Server 2.1 Gentoo Linux |
| Not Vulnerable: |
Webmin Webmin 1.230 Webmin Usermin 1.160 |
Discussion
Webmin / Usermin Remote PAM Authentication Bypass Vulnerability
Webmin and Usermin are susceptible to a remote PAM authentication bypass vulnerability. This issue is present in the 'miniserv.pl' Web server that is bundled with these applications.
Due to insufficient input validation, shell metacharacters may be employed to bypass the authentication mechanism.
Due to the nature of these applications, full system compromise is very likely after gaining access.
Webmin and Usermin are susceptible to a remote PAM authentication bypass vulnerability. This issue is present in the 'miniserv.pl' Web server that is bundled with these applications.
Due to insufficient input validation, shell metacharacters may be employed to bypass the authentication mechanism.
Due to the nature of these applications, full system compromise is very likely after gaining access.
Exploit / POC
Webmin / Usermin Remote PAM Authentication Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Webmin / Usermin Remote PAM Authentication Bypass Vulnerability
Solution:
The vendor has released updated versions of the affected packages to address this issue.
Gentoo has released advisory GLSA 200509-17 to address these issues. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
All Webmin users:
emerge --sync
emerge --ask --oneshot --verbose ">=app-admin/webmin-1.230"
All Usermin users:
emerge --sync
emerge --ask --oneshot --verbose ">=app-admin/usermin-1.160"
Mandriva has released advisory MDKSA-2005:176 to address this issue. Please see the referenced advisory for further information.
SUSE Linux has released security advisory SUSE-SR:2005:024 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Webmin Usermin 1.130
Webmin Usermin 1.140
Webmin Usermin 1.150
Webmin Webmin 1.200
Webmin Webmin 1.210
Webmin Webmin 1.220
Solution:
The vendor has released updated versions of the affected packages to address this issue.
Gentoo has released advisory GLSA 200509-17 to address these issues. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
All Webmin users:
emerge --sync
emerge --ask --oneshot --verbose ">=app-admin/webmin-1.230"
All Usermin users:
emerge --sync
emerge --ask --oneshot --verbose ">=app-admin/usermin-1.160"
Mandriva has released advisory MDKSA-2005:176 to address this issue. Please see the referenced advisory for further information.
SUSE Linux has released security advisory SUSE-SR:2005:024 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Webmin Usermin 1.130
-
Webmin usermin-1.160.tar.gz
http://prdownloads.sourceforge.net/webadmin/usermin-1.160.tar.gz
Webmin Usermin 1.140
-
Webmin usermin-1.160.tar.gz
http://prdownloads.sourceforge.net/webadmin/usermin-1.160.tar.gz
Webmin Usermin 1.150
-
Webmin usermin-1.160.tar.gz
http://prdownloads.sourceforge.net/webadmin/usermin-1.160.tar.gz
Webmin Webmin 1.200
-
Webmin webmin-1.230.tar.gz
http://prdownloads.sourceforge.net/webadmin/webmin-1.230.tar.gz
Webmin Webmin 1.210
-
Webmin webmin-1.230.tar.gz
http://prdownloads.sourceforge.net/webadmin/webmin-1.230.tar.gz
Webmin Webmin 1.220
-
Mandriva webmin-1.220-9.1.20060mdk.noarch.rpm
Mandrivalinux 2006.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva webmin-1.220-9.1.20060mdk.noarch.rpm
Mandrivalinux 2006.0:
http://www1.mandrivalinux.com/en/ftp.php3 -
Webmin webmin-1.230.tar.gz
http://prdownloads.sourceforge.net/webadmin/webmin-1.230.tar.gz
References
Webmin / Usermin Remote PAM Authentication Bypass Vulnerability
References:
References:
- Usermin Change Log (Webmin)
- Webmin Change Log (Webmin)
- Webmin Homepage (Webmin)
- [SNS Advisory No.83] Webmin/Usermin PAM Authentication Bypass Vulnerability ([email protected] (snsadv))