Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: usermin (200302-14)
Date: Mon, 24 Feb 2003 12:49:15
Message-Id: 20030224100754.C89015761@mail2.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200302-14
6 - - ---------------------------------------------------------------------
7
8 PACKAGE : usermin
9 SUMMARY : unauthorized access
10 DATE : 2003-02-24 10:10 UTC
11 EXPLOIT : remote
12 VERSIONS AFFECTED : <1.000
13 FIXED VERSION : 1.000
14
15 - - ---------------------------------------------------------------------
16
17 - From announcement:
18
19 "Due to a remotely exploitable security hole being discovered that
20 effects all previous Webmin releases, version 1.070 is now available
21 for download from http://www.webmin.com/ and mirror sites. This
22 problem was reported by Cintia M. Imanishi, but fortunately there
23 have been no known malicious exploits of it yet. However, all users
24 should upgrade to 1.070 as soon as possible."
25
26 "Also available is Usermin 1.000 which fixes the exact same security
27 hole. It includes the same File Manager features, as well as support
28 for IMAP folders and an IMAP inbox in the Read Mail module."
29
30 Read the full announcement at:
31 http://marc.theaimsgroup.com/?l=webmin-announce&m=104587858408101&w=2
32
33
34 SOLUTION
35
36 It is recommended that all Gentoo Linux users who are running
37 app-admin/usermin upgrade to usermin-1.000 as follows:
38
39 emerge sync
40 emerge -u usermin
41 emerge clean
42
43 - - ---------------------------------------------------------------------
44 aliz@g.o - GnuPG key is available at http://cvs.gentoo.org/~aliz
45 - - ---------------------------------------------------------------------
46 -----BEGIN PGP SIGNATURE-----
47 Version: GnuPG v1.2.1 (GNU/Linux)
48
49 iD8DBQE+We97fT7nyhUpoZMRAoJyAJwIyGaJYx/5seE0gJyAWSJxLJjsjACfcjz5
50 HnsBZk4bNXoP5oW6LMXFqC4=
51 =+8v6
52 -----END PGP SIGNATURE-----