Webmin Plaintext Authentication Credentials Disclosure Vulnerability
BID:4351
Info
Webmin Plaintext Authentication Credentials Disclosure Vulnerability
| Bugtraq ID: | 4351 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 22 2002 12:00AM |
| Updated: | Mar 22 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Ed <[email protected]>. |
| Vulnerable: |
Webmin Webmin 0.93 Webmin Webmin 0.92 -1 Webmin Webmin 0.92 Webmin Webmin 0.91 Webmin Webmin 0.88 Webmin Webmin 0.85 Webmin Webmin 0.80 Webmin Webmin 0.79 Webmin Webmin 0.78 Webmin Webmin 0.77 Webmin Webmin 0.76 Webmin Webmin 0.51 Webmin Webmin 0.42 Webmin Webmin 0.41 Webmin Webmin 0.31 Webmin Webmin 0.22 Webmin Webmin 0.21 Webmin Webmin 0.8.4 Webmin Webmin 0.8.3 Webmin Webmin 0.7 Webmin Webmin 0.6 Webmin Webmin 0.5 Webmin Webmin 0.4 Webmin Webmin 0.3 Webmin Webmin 0.2 Webmin Webmin 0.1 |
| Not Vulnerable: | |
Discussion
Webmin Plaintext Authentication Credentials Disclosure Vulnerability
Webmin is a web-based interface for system administration of Unix and Linux operating systems.
It has been reported that authentication credentials for remote Webmin servers on the network are stored in plaintext by Webmin. With the proper file and directory permissions in place, this should not be an issue in and of itself. However, BugTraq ID 4328 "Webmin Insecure Directory Permissions Vulnerability" describes an issue which may potentially expose these credentials to local attackers.
This vulnerability may also cause remote authentication credentials to be disclosed to a malicious administrator.
Webmin is a web-based interface for system administration of Unix and Linux operating systems.
It has been reported that authentication credentials for remote Webmin servers on the network are stored in plaintext by Webmin. With the proper file and directory permissions in place, this should not be an issue in and of itself. However, BugTraq ID 4328 "Webmin Insecure Directory Permissions Vulnerability" describes an issue which may potentially expose these credentials to local attackers.
This vulnerability may also cause remote authentication credentials to be disclosed to a malicious administrator.
Exploit / POC
Webmin Plaintext Authentication Credentials Disclosure Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Webmin Plaintext Authentication Credentials Disclosure Vulnerability
Solution:
The vendor does not appear to have addressed this issue directly. The other known issue, which involves the creation of sensitive directories and files with insecure default permissions has been addressed in Webmin 0.93. Upgrading to the latest version may help to mitigate this issue. It should be noted that any and all authentication credentials should be changed once the upgrade is performed, to address the possibility of a previous exposure.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The vendor does not appear to have addressed this issue directly. The other known issue, which involves the creation of sensitive directories and files with insecure default permissions has been addressed in Webmin 0.93. Upgrading to the latest version may help to mitigate this issue. It should be noted that any and all authentication credentials should be changed once the upgrade is performed, to address the possibility of a previous exposure.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Webmin Plaintext Authentication Credentials Disclosure Vulnerability
References:
References:
- Webmin Homepage (Webmin)