Alerta de Segurança Debian

DSA-319-1 webmin -- falsificação de Id de sessão

Data do Alerta:
12 Jun 2003
Pacotes Afetados:
webmin
Vulnerável:
Sim
Referência à base de dados de segurança:
Na base de dados do BugTraq (na SecurityFocus): ID BugTraq 6915.
No dicionário CVE do Mitre: CVE-2003-0101.
Informações adicionais:

O script miniserv.pl do pacote webmin não trata adequadamente meta-caracteres, como quebras de linha e enters, em strings com codificação Base64 usadas na autenticação Basic. Esta vulnerabilidade permite que atacantes remotos falsifiquem o Id de sessão e através disso obtenham os privilégios de root.

Na atual distribuição estável (woody), este problema foi corrigido na versão 0.94-7woody1.

A antiga distribuição estável (potato) não contém pacotes webmin.

Na distribuição instável (sid), este problema foi corrigido na versão 1.070-1.

Nós recomendamos que você atualize seus pacotes webmin.

Corrigido em:

Debian GNU/Linux 3.0 (woody)

Fonte:
http://security.debian.org/pool/updates/main/w/webmin/webmin_0.94-7woody1.dsc
http://security.debian.org/pool/updates/main/w/webmin/webmin_0.94-7woody1.diff.gz
http://security.debian.org/pool/updates/main/w/webmin/webmin_0.94.orig.tar.gz
Componente independente de arquitetura:
http://security.debian.org/pool/updates/main/w/webmin/webmin-apache_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-bind8_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-burner_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-cluster-software_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-cluster-useradmin_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-core_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-cpan_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-dhcpd_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-exports_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-fetchmail_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-heartbeat_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-inetd_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-jabber_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-lpadmin_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-mon_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-mysql_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-nis_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-postfix_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-postgresql_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-ppp_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-qmailadmin_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-quota_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-raid_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-samba_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-sendmail_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-software_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-squid_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-sshd_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-ssl_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-status_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-stunnel_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-wuftpd_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin-xinetd_0.94-7woody1_all.deb
http://security.debian.org/pool/updates/main/w/webmin/webmin_0.94-7woody1_all.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/w/webmin/webmin-grub_0.94-7woody1_i386.deb

Checksums MD5 dos arquivos listados estão disponíveis no alerta original.