Usermin Change User Details Remote Denial of Service Vulnerability
BID:18574
CVE-2006-4246 |Info
Usermin Change User Details Remote Denial of Service Vulnerability
| Bugtraq ID: | 18574 |
| Class: | Design Error |
| CVE: |
CVE-2006-4246 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2006 12:00AM |
| Updated: | Sep 15 2006 08:47PM |
| Credit: | Hendrik Weimer is credited with the discovery of this vulnerability. |
| Vulnerable: |
Usermin Usermin 1.0 90 Usermin Usermin 1.0 80 Usermin Usermin 1.0 70 Usermin Usermin 1.0 60 Usermin Usermin 1.0 51 Usermin Usermin 1.0 40 Usermin Usermin 1.0 30 Usermin Usermin 1.0 20 Usermin Usermin 1.0 10 Usermin Usermin 1.0 00 Usermin Usermin 0.990 Usermin Usermin 0.980 Usermin Usermin 0.970 Usermin Usermin 0.960 Usermin Usermin 0.950 Usermin Usermin 0.940 Usermin Usermin 0.930 Usermin Usermin 0.920 Usermin Usermin 0.910 Usermin Usermin 0.90 Usermin Usermin 0.80 Usermin Usermin 0.7 Usermin Usermin 1.110 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
Usermin Usermin 1.220 Usermin Usermin 1.110-3.1 |
Discussion
Usermin Change User Details Remote Denial of Service Vulnerability
Usermin is prone to a remote denial-of-service vulnerability. This issue is due to a design error in the application when setting the user's shell.
An attacker can exploit this issue to change the shell of the superuser account, effectively denying service.
Versions prior to 1.110-3.1 are vulnerable to this issue.
Usermin is prone to a remote denial-of-service vulnerability. This issue is due to a design error in the application when setting the user's shell.
An attacker can exploit this issue to change the shell of the superuser account, effectively denying service.
Versions prior to 1.110-3.1 are vulnerable to this issue.
Exploit / POC
Usermin Change User Details Remote Denial of Service Vulnerability
To exploit this issue, attackers use the vulnerable application itself.
To exploit this issue, attackers use the vulnerable application itself.
Solution / Fix
Usermin Change User Details Remote Denial of Service Vulnerability
Solution:
An advisory has been released to address this issue. Please see the references for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
An advisory has been released to address this issue. Please see the references for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Usermin Change User Details Remote Denial of Service Vulnerability
References:
References:
- Debian Bug report logs - #374609 - usermin-chfn: Root Shell Denial of Service (Hendrik Weimer)
- Usermin - User's Little Helper (OS Reviews)