CVE-2001-1074: High severity webmin webmin vulnerability
Webmin 0.84 and earlier does not properly clear the HTTPAUTHORIZATION environment variable when the web server is restarted, which makes authentication information available to all CGI programs and allows local users to gain privileges.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1074?
CVE-2001-1074 is considered a high severity vulnerability due to the potential for local users to gain unauthorized privileges.
How do I fix CVE-2001-1074?
To fix CVE-2001-1074, upgrade Webmin to a version later than 0.84 that properly clears the HTTP_AUTHORIZATION environment variable.
Which versions of Webmin are affected by CVE-2001-1074?
Webmin versions 0.5 through 0.84 are affected by CVE-2001-1074.
What vulnerabilities does CVE-2001-1074 introduce?
CVE-2001-1074 introduces a vulnerability that allows local users to access sensitive authentication information, leading to potential privilege escalation.
Is there a patch available for CVE-2001-1074?
There is no patch for CVE-2001-1074; the recommended action is to upgrade to a more secure version of Webmin.