CVE-2015-1377: Medium severity webmin vulnerability
Published Feb 10, 2015
·Updated
The Read Mail module in Webmin 1.720 allows local users to read arbitrary files via a symlink attack on an unspecified file.
Affected Software
1 affected component
webmin webmin<=1.720
Event History
Feb 10, 2015
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1377?
CVE-2015-1377 is considered to have medium severity due to local users being able to read arbitrary files.
2
How do I fix CVE-2015-1377?
To fix CVE-2015-1377, upgrade Webmin to version 1.721 or later to mitigate the symlink attack.
3
Who is affected by CVE-2015-1377?
Local users with access to the Webmin Read Mail module on versions up to and including 1.720 are affected by CVE-2015-1377.
4
What type of vulnerability is CVE-2015-1377?
CVE-2015-1377 is a local file read vulnerability that can be exploited through a symlink attack.
5
What software version is impacted by CVE-2015-1377?
CVE-2015-1377 affects Webmin versions up to and including 1.720.