Gentoo: webmin Unauthorized access vulnerability
Summary
- --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200302-12 - --------------------------------------------------------------------- FIXED VERSION : 1.070
- ---------------------------------------------------------------------
From announcement:
"Due to a remotely exploitable security hole being discovered that effects all previous Webmin releases, version 1.070 is now available for download from Webmin and mirror sites. This problem was reported by Cintia M. Imanishi, but fortunately there have been no known malicious exploits of it yet. However, all usersshould upgrade to 1.070 as soon as possible."
Read the full announcement at: http://marc.theaimsgroup.com/?l=webmin-announce&m=104587858408101&w=2
SOLUTION
It is recommended that all Gentoo Linux users who are running app-admin/webmin upgrade to webmin-1.070 as follows:
emerge sync emerge -u webmin emerge clean
...Read the Full Advisory