CVE-2005-3042: High severity Usermin Usermin vulnerability
Published Sep 22, 2005
·Updated
miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when "full PAM conversations" is enabled, allows remote attackers to bypass authentication by spoofing session IDs via certain metacharacters (line feed or carriage return).
Affected Software
2 affected components
Usermin Usermin=1.150
webmin webmin=1.2.20
Remediation
Patch Available
Patch Available
Event History
Sep 22, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3042?
CVE-2005-3042 is considered a high severity vulnerability due to its ability to allow remote attackers to bypass authentication.
2
How do I fix CVE-2005-3042?
To fix CVE-2005-3042, upgrade to Webmin version 1.230 or Usermin version 1.160 or later.
3
Which versions of Webmin are affected by CVE-2005-3042?
CVE-2005-3042 affects Webmin versions prior to 1.230.
4
Which versions of Usermin are affected by CVE-2005-3042?
CVE-2005-3042 affects Usermin versions prior to 1.160.
5
What does CVE-2005-3042 exploit?
CVE-2005-3042 exploits the ability to spoof session IDs when full PAM conversations are enabled.