Lucene search

K
freebsdFreeBSDAE7B7F65-05C7-11D9-B45D-000C41E2CDAD
HistorySep 05, 2004 - 12:00 a.m.

webmin -- insecure temporary file creation at installation time

2004-09-0500:00:00
vuxml.freebsd.org
15

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

EPSS

0

Percentile

5.1%

The Webmin developers documented a security issue in the
release notes for version 1.160:

Fixed a security hole in the maketemp.pl script, used
to create the /tmp/.webmin directory at install time. If
an un-trusted user creates this directory before Webmin
is installed, he could create in it a symbolic link
pointing to a critical file on the system, which would be
overwritten when Webmin writes to the link filename.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchwebmin< 1.150_5UNKNOWN

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

EPSS

0

Percentile

5.1%

Related for AE7B7F65-05C7-11D9-B45D-000C41E2CDAD