Package name
webmin
Date
2011-06-13
Advisory ID
MDVSA-2011:109
Affected versions
2009.0 x86_64 , MES5 i586 , 2010.1 i586 , 2009.0 i586 , CS4.0 i586 , CS4.0 x86_64 , MES5 x86_64 , 2010.1 x86_64

Problem description

A vulnerability was discovered and corrected in webmin:

Cross-site scripting (XSS) vulnerability in Webmin 1.540 and earlier
allows local users to inject arbitrary web script or HTML via a
chfn command that changes the real (aka Full Name) field, related to
useradmin/index.cgi and useradmin/user-lib.pl (CVE-2011-1937).

Packages for 2009.0 are provided as of the Extended Maintenance
Program. Please visit this link to learn more:
http://store.mandriva.com/product_info.php?cPath=149&products_id=490

The updated packages have been upgraded to the 1.550 version which
is not vulnerable to this issue.

Updated packages

2009.0 x86_64

 e99a38af64daaf8d18ef41b79abc9eac  2009.0/x86_64/webmin-1.550-0.2mdv2009.0.noarch.rpm 
 3fd92a2734e26088354b2ab5578fcbb2  2009.0/SRPMS/webmin-1.550-0.2mdv2009.0.src.rpm

MES5 i586

 ee2836bfc1d2704a6d70baabcfd73fd3  mes5/i586/webmin-1.550-0.2mdvmes5.2.noarch.rpm 
 eb15e4033c829d2a69041ed7fae6195d  mes5/SRPMS/webmin-1.550-0.2mdvmes5.2.src.rpm

2010.1 i586

 ab3c0717a236e2f67cf63dcd82e9e1d4  2010.1/i586/webmin-1.550-0.2mdv2010.2.noarch.rpm 
 7ae547003c8cc3e24ece9d9a4db2c057  2010.1/SRPMS/webmin-1.550-0.2mdv2010.2.src.rpm

2009.0 i586

 72a63255fe21815b7e16e13676bf76cd  2009.0/i586/webmin-1.550-0.2mdv2009.0.noarch.rpm 
 3fd92a2734e26088354b2ab5578fcbb2  2009.0/SRPMS/webmin-1.550-0.2mdv2009.0.src.rpm

CS4.0 i586

 79d4b2f9dd4e9a11291e23a5a431bab5  corporate/4.0/i586/webmin-1.550-0.2.20060mlcs4.noarch.rpm 
 eca1fae447edf15165d7330455104d98  corporate/4.0/SRPMS/webmin-1.550-0.2.20060mlcs4.src.rpm

CS4.0 x86_64

 ebaef883448b18903bec6547f061372c  corporate/4.0/x86_64/webmin-1.550-0.2.20060mlcs4.noarch.rpm 
 eca1fae447edf15165d7330455104d98  corporate/4.0/SRPMS/webmin-1.550-0.2.20060mlcs4.src.rpm

MES5 x86_64

 f0b58d569c1f5006bf185d48254c3080  mes5/x86_64/webmin-1.550-0.2mdvmes5.2.noarch.rpm 
 eb15e4033c829d2a69041ed7fae6195d  mes5/SRPMS/webmin-1.550-0.2mdvmes5.2.src.rpm

2010.1 x86_64

 7a9cd08d59472f600969fb697ccd36e5  2010.1/x86_64/webmin-1.550-0.2mdv2010.2.noarch.rpm 
 7ae547003c8cc3e24ece9d9a4db2c057  2010.1/SRPMS/webmin-1.550-0.2mdv2010.2.src.rpm

References