[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    Re: [oss-security] CVE Request: Webmin & Usermin - Read Mail Module Vulnerability
From:       cve-assign () mitre ! org
Date:       2015-01-27 18:07:25
Message-ID: Pine.LNX.4.64.1501271306190.11165 () beijing ! mitre ! org
[Download RAW message or body]


> I need to request 2 CVE's; one for Usermin and one for Webmin.
>
> Both of them are vulnerable to a hardlink arbitrary file access within the 
> Read Mail Module. The end result is the ability to open any file on the 
> server, including root owned files, which could lead to a privilege 
> escalation.
>
> Reference: http://www.webmin.com/index.html
>
> "January 1: Webmin 1.730 and Usermin 1.640 released - This update includes 
> security fixes to produce against malicious links in the Read Mail module..."
>
> Thanks!

Only one identifier is needed.  Use CVE-2015-1377.

---

CVE assignment team, MITRE CVE Numbering Authority M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic