First published: Tue Dec 31 2002(Updated: )
Webmin 0.21 through 1.0 uses the same built-in SSL key for all installations, which allows remote attackers to eavesdrop or highjack the SSL session.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmin Webmin | =0.97 | |
Webmin Webmin | =0.22 | |
Webmin Webmin | =0.99 | |
Webmin Webmin | =0.88 | |
Webmin Webmin | =0.96 | |
Webmin Webmin | =0.51 | |
Webmin Webmin | =0.93 | |
Webmin Webmin | =0.31 | |
Webmin Webmin | =0.42 | |
Webmin Webmin | =1.0.00 | |
Webmin Webmin | =0.92 | |
Webmin Webmin | =0.78 | |
Webmin Webmin | =0.21 | |
Webmin Webmin | =0.77 | |
Webmin Webmin | =0.85 | |
Webmin Webmin | =0.41 | |
Webmin Webmin | =0.95 | |
Webmin Webmin | =0.94 | |
Webmin Webmin | =0.79 | |
Webmin Webmin | =0.76 | |
Webmin Webmin | =0.91 | |
Webmin Webmin | =0.80 | |
Webmin Webmin | =0.98 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1947 is classified as a high severity vulnerability due to its potential to allow remote attackers to eavesdrop on SSL sessions.
To fix CVE-2002-1947, upgrade Webmin to a version later than 1.0 that does not use a shared SSL key.
CVE-2002-1947 affects Webmin versions from 0.21 to 1.0, including 0.21, 0.22, 0.31, 0.42, and up to 0.99.
CVE-2002-1947 is an SSL session hijacking vulnerability that enables attackers to eavesdrop on encrypted communications.
While CVE-2002-1947 was reported in 2002, its exploitability may still be relevant for systems using outdated versions of Webmin.