CVE Vulnerabilities

CVE-2005-0427

Published: May 02, 2005 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The ebuild of Webmin before 1.170-r3 on Gentoo Linux includes the encrypted root password in the miniserv.users file when building a tbz2 of the webmin package, which allows remote attackers to obtain and possibly crack the encrypted password.

Affected Software

Name Vendor Start Version End Version
Webmin Gentoo 1.140 (including) 1.140 (including)
Webmin Gentoo 1.150 (including) 1.150 (including)
Webmin Gentoo 1.160 (including) 1.160 (including)
Webmin Gentoo 1.170-r1 (including) 1.170-r1 (including)
Webmin Gentoo 1.170-r2 (including) 1.170-r2 (including)

References