CVE-2012-2981: Input Validation
Published Sep 11, 2012
·Updated
Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor type name) parameter.
Affected Software
39 affected components
Gentoo Webmin<=1.590
Gentoo Webmin=1.140
Gentoo Webmin=1.150
Gentoo Webmin=1.160
Gentoo Webmin=1.170
Gentoo Webmin=1.180
Gentoo Webmin=1.200
Gentoo Webmin=1.210
Gentoo Webmin=1.220
Gentoo Webmin=1.230
Gentoo Webmin=1.240
Gentoo Webmin=1.260
Gentoo Webmin=1.270
Gentoo Webmin=1.280
Gentoo Webmin=1.290
Gentoo Webmin=1.300
Gentoo Webmin=1.310
Gentoo Webmin=1.320
Gentoo Webmin=1.330
Gentoo Webmin=1.340
Gentoo Webmin=1.370
Gentoo Webmin=1.380
Gentoo Webmin=1.390
Gentoo Webmin=1.400
Gentoo Webmin=1.410
Gentoo Webmin=1.420
Gentoo Webmin=1.430
Gentoo Webmin=1.440
Gentoo Webmin=1.450
Gentoo Webmin=1.470
Gentoo Webmin=1.480
Gentoo Webmin=1.500
Gentoo Webmin=1.510
Gentoo Webmin=1.520
Gentoo Webmin=1.530
Gentoo Webmin=1.550
Gentoo Webmin=1.560
Gentoo Webmin=1.570
Gentoo Webmin=1.580
Remediation
Patch Available
Event History
Sep 11, 2012
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2981?
CVE-2012-2981 has a medium severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2012-2981?
To mitigate CVE-2012-2981, update Webmin to version 1.600 or later, which addresses the vulnerability.
3
Who is affected by CVE-2012-2981?
CVE-2012-2981 affects Webmin versions 1.590 and earlier, particularly on Gentoo systems.
4
What type of attack can exploit CVE-2012-2981?
CVE-2012-2981 can be exploited by authenticated users to execute arbitrary Perl code remotely.
5
How can I determine if my Webmin installation is vulnerable to CVE-2012-2981?
You can determine vulnerability by checking if your Webmin version is 1.590 or earlier.