Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 434776 (CVE-2012-2981) - <app-admin/webmin-1.600: Multiple vulnerabilities (CVE-2012-{2981,2982,2983,4893})
Summary: <app-admin/webmin-1.600: Multiple vulnerabilities (CVE-2012-{2981,2982,2983,4...
Status: RESOLVED FIXED
Alias: CVE-2012-2981
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~1 [noglsa]
Keywords:
Depends on: 438182
Blocks:
  Show dependency tree
 
Reported: 2012-09-12 00:59 UTC by GLSAMaker/CVETool Bot
Modified: 2012-10-15 00:33 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2012-09-12 00:59:22 UTC
CVE-2012-4893 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4893):
  Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi
  in Webmin 1.590 and earlier allow remote attackers to hijack the
  authentication of privileged users for requests that (1) read files or
  execute (2) tar, (3) zip, or (4) gzip commands, a different issue than
  CVE-2012-2982.

CVE-2012-2983 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2983):
  file/edit_html.cgi in Webmin 1.590 and earlier does not perform an
  authorization check before showing a file's unedited contents, which allows
  remote attackers to read arbitrary files via the file field.

CVE-2012-2982 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2982):
  file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users
  to execute arbitrary commands via an invalid character in a pathname, as
  demonstrated by a | (pipe) character.

CVE-2012-2981 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2981):
  Webmin 1.590 and earlier allows remote authenticated users to execute
  arbitrary Perl code via a crafted file associated with the type (aka monitor
  type name) parameter.
Comment 1 Markos Chandras (RETIRED) gentoo-dev 2012-10-14 09:53:29 UTC
This should be fixed in webmin-1.600 which I just bumped to the tree
Comment 2 Sean Amoss (RETIRED) gentoo-dev Security 2012-10-15 00:33:06 UTC
Thanks, Markos. Please also drop vulnerable versions.

Closing noglsa for ~arch only.