CVE-2004-0583: Medium severity Usermin Usermin vulnerability
Published Jun 23, 2004
·Updated
The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote attackers to conduct a brute force attack to guess user IDs and passwords.
Affected Software
14 affected components
Usermin Usermin=1.070
Webmin Webmin=1.1.40
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Remediation
Patch Available
Patch Available
Event History
Jun 23, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0583?
CVE-2004-0583 is considered a medium severity vulnerability due to its potential for brute force attacks.
2
How do I fix CVE-2004-0583?
To fix CVE-2004-0583, update Webmin to version 1.1.41 or higher and Usermin to version 1.071 or higher.
3
Which versions are affected by CVE-2004-0583?
CVE-2004-0583 affects Webmin 1.140 and Usermin 1.070.
4
What type of attack does CVE-2004-0583 allow?
CVE-2004-0583 allows remote attackers to conduct brute force attacks to guess user IDs and passwords.
5
Is there a workaround for CVE-2004-0583 if I cannot update immediately?
A temporary workaround for CVE-2004-0583 is to implement account lockout policies and limit login attempts.