Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: Gentoo Local Security Checks --> Category: infos

[GLSA-200608-11] Webmin, Usermin: File Disclosure Vulnerability Scan


Vulnerability Scan Summary
Webmin, Usermin: File Disclosure

Detailed Explanation for this Vulnerability Test
The remote host is affected by the vulnerability described in GLSA-200608-11
(Webmin, Usermin: File Disclosure)


A vulnerability in both Webmin and Usermin has been discovered by Kenny
Chen, wherein simplify_path is called before the HTML is decoded.

Impact

A non-authenticated user can read any file on the server using a
specially crafted URL.

Workaround

For a temporary workaround, IP Access Control can be setup on Webmin
and Usermin.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3392


Solution:
All Webmin users should update to the latest stable version:
# emerge --sync
# emerge --ask --verbose --oneshot ">=app-admin/webmin-1.290"
All Usermin users should update to the latest stable version:
# emerge --sync
# emerge --ask --verbose --oneshot ">=app-admin/usermin-1.220"


Threat Level: Medium


Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.