Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 438182 - New ebuild: app-admin/webmin-1.600 (upstream fixes multiple vulnerabilities)
Summary: New ebuild: app-admin/webmin-1.600 (upstream fixes multiple vulnerabilities)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: Highest enhancement (vote)
Assignee: Markos Chandras (RETIRED)
URL: http://www.kb.cert.org/vuls/id/788478
Whiteboard:
Keywords: EBUILD
Depends on:
Blocks: CVE-2012-2981
  Show dependency tree
 
Reported: 2012-10-12 22:51 UTC by PhobosK
Modified: 2012-10-14 09:52 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
The new webmin-1.600.ebuild (webmin-1.600.ebuild,8.72 KB, text/plain)
2012-10-12 22:51 UTC, PhobosK
Details

Note You need to log in before you can comment on or make changes to this bug.
Description PhobosK 2012-10-12 22:51:55 UTC
Created attachment 326414 [details]
The new webmin-1.600.ebuild

There is a new upstream version of Webmin - 1.600.
The version fixes multiple vulnerabilities (see http://www.kb.cert.org/vuls/id/788478) and introduces some new features and translations. For a full Changelog see http://www.webmin.com/changes.html


The new ebuild adds a forced net-dns/dnssec-tools dependency for security and Gentoo compliance installation reasons.
Nothing in the setup/install script/procedure has been changed.


NOTES: 
1. The new upstream 1.600 version closes the CVE-2012-2981, CVE-2012-2982 and CVE-2012-2983 vulnerabilities. So probably all Webmin versions prior to 1.600 should be removed from Gentoo tree.
2. The reported CVE-2012-4893 (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-4893) is not an actual vulnerability but a Webmin feature. The install procedure of Webmin (incl. the one used by the ebuild/s) by default forces the option "referers_none=1" in /etc/webmin/config , which doesn't allow any cross-site request forgery (CSRF) exploits without the user being informed and without his explicit consent to allow it.
Comment 1 Markos Chandras (RETIRED) gentoo-dev 2012-10-14 09:52:55 UTC
+*webmin-1.600 (14 Oct 2012)
+
+  14 Oct 2012; Markos Chandras <hwoarang@gentoo.org> +webmin-1.600.ebuild:
+  Version bump. Thanks to PhobosK <phobosk@fastmail.fm>. Bug #438182
+