Mandrake Linux Security Advisory : webmin (MDKSA-2002:033)

High Nessus Plugin ID 13939


The remote Mandrake Linux host is missing one or more security updates.


A vulnerability exists in all versions of Webmin prior to 0.970 that allows a remote attacker to login to Webmin as any user. All users of Webmin are encouraged to upgrade immediately.

Users of Mandrake Linux 8.0 and earlier will need to install some additional perl modules for this new version of webmin to work correctly.


Update the affected perl-Authen-PAM, perl-Net_SSLeay and / or webmin packages.

See Also

Plugin Details

Severity: High

ID: 13939

File Name: mandrake_MDKSA-2002-033.nasl

Version: $Revision: 1.13 $

Type: local

Published: 2004/07/31

Modified: 2013/05/31

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:perl-Authen-PAM, p-cpe:/a:mandriva:linux:perl-Net_SSLeay, p-cpe:/a:mandriva:linux:webmin, cpe:/o:mandrakesoft:mandrake_linux:7.1, cpe:/o:mandrakesoft:mandrake_linux:7.2, cpe:/o:mandrakesoft:mandrake_linux:8.0, cpe:/o:mandrakesoft:mandrake_linux:8.1, cpe:/o:mandrakesoft:mandrake_linux:8.2

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 2002/05/21

Reference Information

CVE: CVE-2002-0757

MDKSA: 2002:033