The ebuild of Webmin before 1.170-r3 on Gentoo Linux includes the encrypted root password in the miniserv.users file when building a tbz2 of the webmin package, which allows remote attackers to obtain and possibly crack the encrypted password.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Webmin | Gentoo | 1.140 (including) | 1.140 (including) |
Webmin | Gentoo | 1.150 (including) | 1.150 (including) |
Webmin | Gentoo | 1.160 (including) | 1.160 (including) |
Webmin | Gentoo | 1.170-r1 (including) | 1.170-r1 (including) |
Webmin | Gentoo | 1.170-r2 (including) | 1.170-r2 (including) |