CVE-2012-2983: Medium severity Gentoo Webmin vulnerability
Published Sep 11, 2012
·Updated
file/edithtml.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote attackers to read arbitrary files via the file field.
Affected Software
39 affected components
Gentoo Webmin<=1.590
Gentoo Webmin=1.140
Gentoo Webmin=1.150
Gentoo Webmin=1.160
Gentoo Webmin=1.170
Gentoo Webmin=1.180
Gentoo Webmin=1.200
Gentoo Webmin=1.210
Gentoo Webmin=1.220
Gentoo Webmin=1.230
Gentoo Webmin=1.240
Gentoo Webmin=1.260
Gentoo Webmin=1.270
Gentoo Webmin=1.280
Gentoo Webmin=1.290
Gentoo Webmin=1.300
Gentoo Webmin=1.310
Gentoo Webmin=1.320
Gentoo Webmin=1.330
Gentoo Webmin=1.340
Gentoo Webmin=1.370
Gentoo Webmin=1.380
Gentoo Webmin=1.390
Gentoo Webmin=1.400
Gentoo Webmin=1.410
Gentoo Webmin=1.420
Gentoo Webmin=1.430
Gentoo Webmin=1.440
Gentoo Webmin=1.450
Gentoo Webmin=1.470
Gentoo Webmin=1.480
Gentoo Webmin=1.500
Gentoo Webmin=1.510
Gentoo Webmin=1.520
Gentoo Webmin=1.530
Gentoo Webmin=1.550
Gentoo Webmin=1.560
Gentoo Webmin=1.570
Gentoo Webmin=1.580
Remediation
Patch Available
Event History
Sep 11, 2012
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2983?
CVE-2012-2983 has a medium severity level due to the potential for unauthorized file access.
2
How do I fix CVE-2012-2983?
To fix CVE-2012-2983, update Webmin to version 1.590 or later to ensure proper authorization checks are in place.
3
What type of attacks can result from CVE-2012-2983?
CVE-2012-2983 allows remote attackers to read arbitrary files, which can lead to data leakage and potential further exploitation.
4
Which versions of Webmin are affected by CVE-2012-2983?
CVE-2012-2983 affects Webmin versions 1.590 and earlier.
5
Is there a workaround for CVE-2012-2983 if I cannot update?
A possible workaround for CVE-2012-2983 is to restrict access to the Webmin interface to trusted IPs until an update can be applied.