发布时间 :2004-08-06 00:00:00
修订时间 :2016-10-17 22:46:22

[原文]The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote attackers to conduct a brute force attack to guess user IDs and passwords.



Debian Security Advisory DSA 526-1 - Two vulnerabilities in Webmin 1.140 allow remote attackers to bypass access control rules and the ability to brute force IDs and passwords.

Package        : webmin
Vulnerability  : several
Problem-Type   : remote
Debian-specific: no
CVE Ids        : CAN-2004-0582 CAN-2004-0583

Two vulnerabilities were discovered in webmin:

CAN-2004-0582: Unknown vulnerability in Webmin 1.140 allows remote
 attackers to bypass access control rules and gain read access to
 configuration information for a module.

CAN-2004-0583: The account lockout functionality in (1) Webmin 1.140
 and (2) Usermin 1.070 does not parse certain character strings, which
 allows remote attackers to conduct a brute force attack to guess user
 IDs and passwords.

For the current stable distribution (woody), these problems have been
fixed in version 0.94-7woody2.

For the unstable distribution (sid), these problems have been fixed in
version 1.150-1.

We recommend that you update your webmin package.

- 漏洞描述

Webmin contains a flaw that may allow a remote denial of service. The issue is triggered when a malicious user attempts logon with bogus usernames or passwords, and may result in loss of availability for arbitrary Webmin users.

- 解决方案

Upgrade to version 1.150 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Webmin And Usermin Account Lockout Bypass Vulnerability
Input Validation Error 10523
Yes No
2004-06-11 12:00:00 2009-07-12 05:16:00
Discovery of this issue is credited to Keigo Yamazaki.

- 漏洞讨论

Webmin and Usermin are affected by an account lockout bypass vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input.

This issue may be leveraged to carry out brute force authentication attacks against the affected computer; facilitating unauthorized access to the Webmin and Usermin accounts as well as the affected computer. It has been reported that this issue can also be leveraged to prevent users from logging in, although how this occurs is unspecified.

- 漏洞利用

No exploit is required to leverage this issue.

- 解决方案

The vendor has released upgrades dealing with this issue.

Debian GNU/Linux has released advisory DSA 526-1 addressing this issue. Please see the referenced advisory for further information.

Mandrake Linux has released advisory MDKSA-2004:074 addressing this issue. Please see the referenced advisory for further information.

Turbolinux has released advisory 20050207 [TURBOLINUX SECURITY INFO] 07/Feb/2005 to address various issues. Please see the referenced advisory for more information.

