-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
--------------------------------------------------------------------------
Turbolinux Security Advisory TLSA-2003-12
http://www.turbolinux.co.jp/security/
security-team@turbolinux.co.jp
--------------------------------------------------------------------------
Original released date : 28 Feb 2003
Last revised : 01 Apr 2003
Package : webmin
Summry : Session ID vulnerability
More information :
If a specific data is transmitted to the Webmin,
the Webmin mistakenly transmits the Session ID which included
the information of user who logined.
Impact :
The remote third party is able to login to webmin.
Affected Products :
- Turbolinux 8 Server
- Turbolinux 8 Workstation
- Turbolinux 7 Server
Solution :
Please use turbopkg tool to apply the update.
If you need to confirm the version of current installed
package, please issue rpm command as :
# rpm -qa | grep PACKAGE-NAME
<Turbolinux 8 Server>
Source Packages
Size : MD5
webmin-1.070-1.src.rpm
6929243 b8ac9fe3c918db7d303a66fa3547dde4
Binary Packages
Size : MD5
webmin-1.070-1.noarch.rpm
6036063 b09ac821a2eeb87cfb8d84671af42f98
<Turbolinux 8 Workstation>
Source Packages
Size : MD5
webmin-1.070-1.src.rpm
6929243 b7aec8924795ac971beaadd8dade4a4e
Binary Packages
Size : MD5
webmin-1.070-1.noarch.rpm
6037769 717422a9033274d88ff970d80efefaef
<Turbolinux 7 Server>
Source Packages
Size : MD5
webmin-1.070-1.src.rpm
6929243 0c1bdb87c0136c2336ee7fad44e0ef8a
Binary Packages
Size : MD5
webmin-1.070-1.noarch.rpm
6034053 c2924b0a95429590b9a1167186c2792e
References :
Webmin Change Log
http://www.webmin.com/changes.html
--------------------------------------------------------------------------
Revision History
28 Feb 2003 Initial release
01 Apr 2003 modifyed file size
--------------------------------------------------------------------------
Copyright(C) 2003 Turbolinux, Inc. All rights reserved.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
iD8DBQE+iVrwK0LzjOqIJMwRAnk+AKCn0lnUrsQJ3iZabDS001SrG8IyqgCcCeiN
VqQ03p8QxN4U8zGDx7DS20k=
=xnJw
-----END PGP SIGNATURE-----