CVE-2012-2982: Medium severity Gentoo Webmin vulnerability
Published Sep 11, 2012
·Updated
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.
Affected Software
39 affected components
Gentoo Webmin<=1.590
Gentoo Webmin=1.140
Gentoo Webmin=1.150
Gentoo Webmin=1.160
Gentoo Webmin=1.170
Gentoo Webmin=1.180
Gentoo Webmin=1.200
Gentoo Webmin=1.210
Gentoo Webmin=1.220
Gentoo Webmin=1.230
Gentoo Webmin=1.240
Gentoo Webmin=1.260
Gentoo Webmin=1.270
Gentoo Webmin=1.280
Gentoo Webmin=1.290
Gentoo Webmin=1.300
Gentoo Webmin=1.310
Gentoo Webmin=1.320
Gentoo Webmin=1.330
Gentoo Webmin=1.340
Gentoo Webmin=1.370
Gentoo Webmin=1.380
Gentoo Webmin=1.390
Gentoo Webmin=1.400
Gentoo Webmin=1.410
Gentoo Webmin=1.420
Gentoo Webmin=1.430
Gentoo Webmin=1.440
Gentoo Webmin=1.450
Gentoo Webmin=1.470
Gentoo Webmin=1.480
Gentoo Webmin=1.500
Gentoo Webmin=1.510
Gentoo Webmin=1.520
Gentoo Webmin=1.530
Gentoo Webmin=1.550
Gentoo Webmin=1.560
Gentoo Webmin=1.570
Gentoo Webmin=1.580
Remediation
Patch Available
Event History
Sep 11, 2012
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2982?
CVE-2012-2982 has a medium severity rating as it allows remote authenticated users to execute arbitrary commands.
2
How do I fix CVE-2012-2982?
To fix CVE-2012-2982, upgrade to Webmin version 1.590 or later to eliminate the vulnerability.
3
Who is affected by CVE-2012-2982?
CVE-2012-2982 affects all versions of Webmin up to and including 1.590.
4
What type of vulnerability is CVE-2012-2982?
CVE-2012-2982 is a command injection vulnerability due to improper handling of input in file/show.cgi.
5
Can CVE-2012-2982 be exploited remotely?
Yes, CVE-2012-2982 can be exploited remotely by authenticated users.