First published: Fri Dec 31 1999(Updated: )
Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmin | =0.22 | |
Webmin | =0.4 | |
Webmin | =0.31 | |
Webmin | =0.42 | |
Webmin | =0.21 | |
Webmin | =0.2 | |
Webmin | =0.41 | |
Webmin | =0.3 | |
Webmin | =0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1074 has a critical severity level as it allows remote attackers to perform brute force password cracking.
To fix CVE-1999-1074, upgrade to a version of Webmin that is later than 0.5, which restricts invalid password attempts.
CVE-1999-1074 affects all versions of Webmin before 0.5 including versions 0.1 through 0.42.
CVE-1999-1074 can potentially allow unauthorized users to gain administrative privileges by successfully guessing user passwords.
While CVE-1999-1074 is an older vulnerability, if outdated versions of Webmin are still in use, it poses a significant security risk.