Overview
Webmin 1.580, and possibly earlier versions, has been reported to contain input validation vulnerabilities.
Description
The advisories from American Information Security Group report the following vulnerabilities. CWE-20: Improper Input Validation - CVE-2012-2981 |
Impact
An authenticated attacker may be able to execute arbitrary commands. |
Solution
We are currently unaware of a practical solution to this problem. The vendor is aware of the vulnerabilities and has patches available in the development branch but an official version including the patches was not available at the time of publication. |
Restrict access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 8.5 | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Temporal | 6.9 | E:POC/RL:TF/RC:C |
Environmental | 5.2 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
- http://www.webmin.com/
- https://github.com/webmin/webmin/commit/ed7365064c189b8f136a9f952062249167d1bd9e
- https://github.com/webmin/webmin/commit/1f1411fe7404ec3ac03e803cfa7e01515e71a213
- https://github.com/webmin/webmin/commit/4cd7bad70e23e4e19be8ccf7b9f245445b2b3b80
- http://americaninfosec.com/research/index.html
- http://www.americaninfosec.com/research/dossiers/AISG-12-000.pdf
- http://www.americaninfosec.com/research/dossiers/AISG-12-001.pdf
- http://www.americaninfosec.com/research/dossiers/AISG-12-002.pdf
Acknowledgements
Thanks to the American Information Security Group for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
CVE IDs: | CVE-2012-2981, CVE-2012-2982, CVE-2012-2983 |
Date Public: | 2012-09-06 |
Date First Published: | 2012-09-06 |
Date Last Updated: | 2014-08-15 03:03 UTC |
Document Revision: | 27 |