Mandrake Linux Security Advisory : webmin (MDKSA-2004:074)
Medium Nessus Plugin ID 14172
SynopsisThe remote Mandrake Linux host is missing a security update.
DescriptionUnknown vulnerability in Webmin 1.140 allows remote attackers to bypass access control rules and gain read access to configuration information for a module. (CVE-2004-0582)
The account lockout functionality in Webmin 1.140 does not parse certain character strings, which allows remote attackers to conduct a brute-force attack to guess user IDs and passwords. (CVE-2004-0583)
The updated packages are patched to correct the problem.
SolutionUpdate the affected webmin package.