Webmin Insecure Directory Permissions Vulnerability
BID:4328
Info
Webmin Insecure Directory Permissions Vulnerability
| Bugtraq ID: | 4328 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 20 2002 12:00AM |
| Updated: | Mar 20 2002 12:00AM |
| Credit: | Discovery of this issue is credited to <[email protected]>. |
| Vulnerable: |
Webmin Webmin 0.92 -1 Webmin Webmin 0.92 |
| Not Vulnerable: |
Webmin Webmin 0.93 |
Discussion
Webmin Insecure Directory Permissions Vulnerability
Webmin is a web-based interface for system administration of Unix and Linux operating systems.
It has been reported that Webmin, when installed from a RPM, creates the /var/webmin directory with world-readable permissions. If command logging is enabled, it may be possible for a local attacker to read the root user's cookie-based authentication credentials. It may be possible for a local attacker to hijack the Webmin session of the root user with these credentials.
This issue was reported for version 0.92. Earlier versions may also be affected.
The directory /etc/webmin/servers/ is also created with similar insecure permissions. Authentication credentials are also stored in plaintext and may be disclosed as a result of this issue. This vulnerability is described in BugTraq ID 4351 "Webmin Plaintext Authentication Credentials Vulnerability".
Webmin is a web-based interface for system administration of Unix and Linux operating systems.
It has been reported that Webmin, when installed from a RPM, creates the /var/webmin directory with world-readable permissions. If command logging is enabled, it may be possible for a local attacker to read the root user's cookie-based authentication credentials. It may be possible for a local attacker to hijack the Webmin session of the root user with these credentials.
This issue was reported for version 0.92. Earlier versions may also be affected.
The directory /etc/webmin/servers/ is also created with similar insecure permissions. Authentication credentials are also stored in plaintext and may be disclosed as a result of this issue. This vulnerability is described in BugTraq ID 4351 "Webmin Plaintext Authentication Credentials Vulnerability".
Solution / Fix
Webmin Insecure Directory Permissions Vulnerability
Solution:
The vendor has addressed this issue in Webmin 0.93. After upgrading, users are advised to change any and all authentication credentials. An additional vulnerability has been discovered which may cause authentication credentials to be disclosed.
Webmin Webmin 0.92 -1
Webmin Webmin 0.92
Solution:
The vendor has addressed this issue in Webmin 0.93. After upgrading, users are advised to change any and all authentication credentials. An additional vulnerability has been discovered which may cause authentication credentials to be disclosed.
Webmin Webmin 0.92 -1
-
Webmin webmin-0.93.tar.gz
http://www.webmin.com/download/webmin-0.93.tar.gz
Webmin Webmin 0.92
-
Webmin webmin-0.93.tar.gz
http://www.webmin.com/download/webmin-0.93.tar.gz