First published: Wed Jun 23 2004(Updated: )
The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote attackers to conduct a brute force attack to guess user IDs and passwords.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmin Usermin | =1.070 | |
Webmin | =1.1.40 | |
Debian | =3.0 | |
Debian | =3.0 | |
Debian | =3.0 | |
Debian | =3.0 | |
Debian | =3.0 | |
Debian | =3.0 | |
Debian | =3.0 | |
Debian | =3.0 | |
Debian | =3.0 | |
Debian | =3.0 | |
Debian | =3.0 | |
Debian | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0583 is considered a medium severity vulnerability due to its potential for brute force attacks.
To fix CVE-2004-0583, update Webmin to version 1.1.41 or higher and Usermin to version 1.071 or higher.
CVE-2004-0583 affects Webmin 1.140 and Usermin 1.070.
CVE-2004-0583 allows remote attackers to conduct brute force attacks to guess user IDs and passwords.
A temporary workaround for CVE-2004-0583 is to implement account lockout policies and limit login attempts.