Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:EXPLOIT:WEBMIN-FS-INT

Severity

High

Recommended

No

Category

HTTP

Keywords

Webmin Format String Integer Wrap

Release Date

2010/04/05

Update Number

1647

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Webmin Format String Integer Wrap


This signature detects attempts to exploit a known vulnerability in Webmin. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.

Extended Description

Perl is prone to a format-string vulnerability because it fails to properly handle format specifiers in formatted-printing functions. An attacker may leverage this issue to write to arbitrary process memory, facilitating code execution in the context of the Perl interpreter process. This can result in unauthorized remote access. Developers should treat the formatted-printing functions in Perl as equivalently vulnerable to exploits as the C library versions and should properly sanitize all data passed in the format-specifier argument. All applications that use formatted-printing functions in an unsafe manner should be considered exploitable.

Affected Products

  • Apple Mac OS X 10.3.9
  • Apple Mac OS X 10.4.8
  • Apple Mac OS X Server 10.3.9
  • Apple Mac OS X Server 10.4.8
  • Conectiva Linux 10.0.0
  • Curtis Hawthorne TN3270RG 1.0.0 .0
  • Curtis Hawthorne TN3270RG 1.0.1
  • Curtis Hawthorne TN3270RG 1.1.0 .0
  • Debian Linux 3.1.0
  • Debian Linux 3.1.0 Alpha
  • Debian Linux 3.1.0 Amd64
  • Debian Linux 3.1.0 Arm
  • Debian Linux 3.1.0 Hppa
  • Debian Linux 3.1.0 Ia-32
  • Debian Linux 3.1.0 Ia-64
  • Debian Linux 3.1.0 M68k
  • Debian Linux 3.1.0 Mips
  • Debian Linux 3.1.0 Mipsel
  • Debian Linux 3.1.0 Ppc
  • Debian Linux 3.1.0 S/390
  • Debian Linux 3.1.0 Sparc
  • Gentoo Linux
  • HP Internet Express 6.3
  • HP Internet Express 6.4
  • HP Tru64 5.1.0 A PK6
  • HP Tru64 5.1.0 A PK6 (BL24)
  • HP Tru64 5.1.0 B-2 PK4
  • HP Tru64 5.1.0 B-2 PK4 (BL25)
  • HP Tru64 5.1.0 B-3
  • IPCop 1.4.20
  • Larry Wall Perl 5.0.0 03
  • Larry Wall Perl 5.0.0 04
  • Larry Wall Perl 5.0.0 04 04
  • Larry Wall Perl 5.0.0 04 05
  • Larry Wall Perl 5.0.0 05
  • Larry Wall Perl 5.0.0 05 003
  • Larry Wall Perl 5.6.0
  • Larry Wall Perl 5.6.1
  • Larry Wall Perl 5.8.0
  • Larry Wall Perl 5.8.0 .0-88.3
  • Larry Wall Perl 5.8.1
  • Larry Wall Perl 5.8.3
  • Larry Wall Perl 5.8.4
  • Larry Wall Perl 5.8.4 -1
  • Larry Wall Perl 5.8.4 -2
  • Larry Wall Perl 5.8.4 -2.3
  • Larry Wall Perl 5.8.4 -3
  • Larry Wall Perl 5.8.4 -4
  • Larry Wall Perl 5.8.4 -5
  • Larry Wall Perl 5.8.5
  • Larry Wall Perl 5.8.6
  • Larry Wall Perl 5.8.7
  • Larry Wall Perl 5.9.2
  • Mandriva Corporate Server 2.1.0
  • Mandriva Corporate Server 2.1.0 X86 64
  • Mandriva Corporate Server 3.0.0
  • Mandriva Corporate Server 3.0.0 X86 64
  • Mandriva Linux Mandrake 10.1.0
  • Mandriva Linux Mandrake 10.1.0 X86 64
  • Mandriva Linux Mandrake 10.2.0
  • Mandriva Linux Mandrake 10.2.0 X86 64
  • Mandriva Linux Mandrake 2006.0.0
  • Mandriva Linux Mandrake 2006.0.0 X86 64
  • Mandriva Multi Network Firewall 2.0.0
  • OpenBSD 3.7
  • OpenBSD 3.8
  • OpenPKG 2.3.0
  • OpenPKG 2.4.0
  • OpenPKG 2.5.0
  • OpenPKG Current
  • Red Hat Desktop 4.0.0
  • Red Hat Enterprise Linux AS 4
  • Red Hat Enterprise Linux ES 4
  • Red Hat Enterprise Linux WS 4
  • Red Hat Fedora Core1
  • Red Hat Fedora Core2
  • Red Hat Fedora Core3
  • Red Hat Fedora Core4
  • Red Hat Linux 9.0.0 I386
  • Sun Solaris 10 Sparc
  • Sun Solaris 10 X86
  • SuSE Linux Desktop 1.0.0
  • SuSE Linux Personal 10.0.0 OSS
  • SuSE Linux Personal 8.2.0
  • SuSE Linux Personal 9.0.0
  • SuSE Linux Personal 9.0.0 X86 64
  • SuSE Linux Personal 9.1.0
  • SuSE Linux Personal 9.1.0 X86 64
  • SuSE Linux Personal 9.2.0
  • SuSE Linux Personal 9.2.0 X86 64
  • SuSE Linux Personal 9.3.0
  • SuSE Linux Personal 9.3.0 X86 64
  • SuSE Linux Professional 10.0.0
  • SuSE Linux Professional 10.0.0 OSS
  • SuSE Linux Professional 8.2.0
  • SuSE Linux Professional 9.0.0
  • SuSE Linux Professional 9.0.0 X86 64
  • SuSE Linux Professional 9.1.0
  • SuSE Linux Professional 9.1.0 X86 64
  • SuSE Linux Professional 9.2.0
  • SuSE Linux Professional 9.2.0 X86 64
  • SuSE Linux Professional 9.3.0
  • SuSE Linux Professional 9.3.0 X86 64
  • SuSE Novell Linux Desktop 9.0.0
  • SuSE Open-Enterprise-Server 9.0.0
  • SuSE SUSE Linux Enterprise Server 8
  • SuSE SUSE Linux Enterprise Server 9
  • SuSE SuSE Linux Openexchange Server 4.0.0
  • SuSE SUSE LINUX Retail Solution 8.0.0
  • SuSE SuSE Linux School Server for i386
  • SuSE SuSE Linux Standard Server 8.0.0
  • SuSE UnitedLinux 1.0.0
  • Trustix Secure Enterprise Linux 2.0.0
  • Trustix Secure Linux 2.2.0
  • Trustix Secure Linux 3.0.0
  • Ubuntu Ubuntu Linux 4.1.0 Ia32
  • Ubuntu Ubuntu Linux 4.1.0 Ia64
  • Ubuntu Ubuntu Linux 4.1.0 Ppc
  • Ubuntu Ubuntu Linux 5.0.0 4 Amd64
  • Ubuntu Ubuntu Linux 5.0.0 4 I386
  • Ubuntu Ubuntu Linux 5.0.0 4 Powerpc
  • Ubuntu Ubuntu Linux 5.10.0 Amd64
  • Ubuntu Ubuntu Linux 5.10.0 I386
  • Ubuntu Ubuntu Linux 5.10.0 Powerpc
  • Webmin Usermin 0.4.0
  • Webmin Usermin 0.5.0
  • Webmin Usermin 0.6.0
  • Webmin Usermin 0.7.0
  • Webmin Usermin 0.8.0
  • Webmin Usermin 0.9.0
  • Webmin Usermin 0.91.0
  • Webmin Usermin 0.92.0
  • Webmin Usermin 0.93.0
  • Webmin Usermin 0.94.0
  • Webmin Usermin 0.95.0
  • Webmin Usermin 0.96.0
  • Webmin Usermin 0.97.0
  • Webmin Usermin 0.98.0
  • Webmin Usermin 0.99.0
  • Webmin Usermin 1.0.0
  • Webmin Usermin 1.110.0
  • Webmin Usermin 1.120.0
  • Webmin Usermin 1.130.0
  • Webmin Usermin 1.140.0
  • Webmin Usermin 1.150.0
  • Webmin Usermin 1.160.0
  • Webmin Usermin 1.170.0
  • Webmin 0.1.0
  • Webmin 0.2.0
  • Webmin 0.21.0
  • Webmin 0.22.0
  • Webmin 0.3.0
  • Webmin 0.31.0
  • Webmin 0.4.0
  • Webmin 0.41.0
  • Webmin 0.42.0
  • Webmin 0.5.0
  • Webmin 0.5.0 x
  • Webmin 0.51.0
  • Webmin 0.6.0
  • Webmin 0.7.0
  • Webmin 0.76.0
  • Webmin 0.77.0
  • Webmin 0.78.0
  • Webmin 0.79.0
  • Webmin 0.80.0
  • Webmin 0.8.3
  • Webmin 0.8.4
  • Webmin 0.85.0
  • Webmin 0.8.5 Red Hat
  • Webmin 0.88.0
  • Webmin 0.89.0
  • Webmin 0.91.0
  • Webmin 0.92.0
  • Webmin 0.92.0 -1
  • Webmin 0.93.0
  • Webmin 0.94.0
  • Webmin 0.950.0
  • Webmin 0.960.0
  • Webmin 0.970.0
  • Webmin 0.980.0
  • Webmin 0.990.0
  • Webmin 1.0.0 00
  • Webmin 1.0.0 20
  • Webmin 1.0.0 50
  • Webmin 1.0.0 60
  • Webmin 1.0.0 70
  • Webmin 1.0.0 80
  • Webmin 1.0.0 90
  • Webmin 1.100.0
  • Webmin 1.110.0
  • Webmin 1.121.0
  • Webmin 1.130.0
  • Webmin 1.140.0
  • Webmin 1.150.0
  • Webmin 1.160.0
  • Webmin 1.170.0
  • Webmin 1.180.0
  • Webmin 1.190.0
  • Webmin 1.200.0
  • Webmin 1.210.0
  • Webmin 1.220.0
  • Webmin 1.230.0
  • Webmin 1.240.0

References

  • BugTraq: 15629
  • CVE: CVE-2005-3912

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out