Webmin 0.92, when installed from an RPM, creates /var/webmin with insecure permissions (world readable), which could allow local users to read the root users cookie-based authentication credentials and possibly hijack the root users session using the credentials.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Webmin | Webmin | 0.92 (including) | 0.92 (including) |
Webmin | Webmin | 0.92.1 (including) | 0.92.1 (including) |