Recent Articles

Seeing Perl In Google Code
Google's release of a code repository for open source projects has a number of languages represented, including Perl.

Perl Plus Jifty Equals Hiveminder
Yes, Jifty is another web application builder, and yes, Hiveminder is another to-do list; but it is Perl that made them possible.

Perl Bootcamp Saddles Up For Germany
The next Big Nerd Ranch session of Perl Bootcamp occurs in Germany in September, and will cover Intermediate...

Perl Coders Get New GTK+ Release
Programmers on Perl and other languages can take advantage of the latest stable release of the GTK+...

Yet Another Perl Conference A Week Away
YAPC:NA 2006 takes place June 26th-28th in Chicago, with Larry Wall and Damian Conway providing the keynotes that will sandwich the conference's events...


09.05.06


Webmin, Usermin Need Updates

By David A. Utter

The French Security Incident Response Team (FrSIRT) has reported a pair of vulnerabilities in Webmin and Usermin that could be exploited by remote attackers.

FrSIRT said in its advisory that the pair of flaws pose problems for users of the Webmin and Usermin web-based interfaces. Both are written in Perl 5 and employ CGI scripts deliver their functionality.

The advisory described the two issues, as reported to FrSIRT by Keigo Yamazaki, Little eArth Corporation:

The first issue is due to an error when handling malformed URLs, which could be exploited by attackers to cause malicious scripting code to be executed by the user's browser.

The second flaw is due to an error when handling malformed URLs, which could be exploited by attackers to display the source code or arbitrary CGI and Perl scripts.

The Casino Affiliate Convention
Register Early and save!

The flaws pose a moderate risk to systems running vulnerable versions of Webmin, as they are remotely exploitable. Cross-site scripting would be the attack vector used, according to the information posted at Secunia about the issues:

1) Some input passed in a NULL character ("%00") in the URL isn't properly verified before being used. This can be exploited to disclose the source code of arbitrary CGI and Perl programs.

2) Some input passed in a NULL character ("%00") in the URL isn't properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

Webmin developers have fixed both vulnerabilities in the development version of Webmin, 1.296, and Usermin, version 1.226.

System administrators on Unix use Webmin to make configuration changes for services and manage accounts. Usermin provides an interface for regular users to read mail and do other user-level functions. Blogger Chris Dorner hosts a walkthrough of Webmin and screenshots of it in action.

About the Author:
David Utter is a staff writer for WebProNews covering technology and business.


About PerlProNews
PerlProNews is a collection of news and commentary designed to keep you in step with the ever evolving landscape of Perl environments. News and Advice for Perl Professionals

PerlProNews is brought to you by:

SecurityConfig.com NetworkingFiles.com
NetworkNewz.com WebProASP.com
PerlProNews.com SQLProNews.com
SysAdminNews DevWebPro.com
LinuxProNews.com WirelessProNews.com
CProgrammingTrends.com ITCertificationNews.com


-- PerlProNews
is an iEntry, Inc. publication --
iEntry, 2549 Richmond Rd. Lexington KY, 40509
2006 iEntry, Inc.  All Rights Reserved  Privacy Policy  Legal

archives | advertising info | news headlines | free newsletters | comments/feedback | submit article



Database Forum News and Advice for Perl Professionals PerlProNews News Archives About Us Feedback PerlProNews.com About Article Archive News Downloads WebProWorld Forums iEntry Advertise Contact Jayde