CVE

Id
6930  
CVE No.
CVE-2003-0101  
Status
Candidate  
Description
miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root privileges.  
Phase
Modified (20080207)  
Votes
ACCEPT(4) Armstrong, Cole, Green, Jones | NOOP(2) Christey, Cox  
Comments
Christey> SGI:20030602-01-I | The "websetup v 3.5 package from IRIX 6.5.20 Applications CD" | uses Webmin; may wish to add this name to the description. | Christey> DEBIAN:DSA-319 | Christey> CIAC:N-058 | URL:http://www.ciac.org/ciac/bulletins/n-058.shtml | ENGARDE:ESA-20030225-006 | URL:http://archives.neohapsis.com/archives/linux/engarde/2003-q1/0008.html | HP:HPSBUX0303-250 | URL:http://archives.neohapsis.com/archives/hp/2003-q1/0063.html | BID:6915 | URL:http://www.securityfocus.com/bid/6915