Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:EXPLOIT:WEBMIN-FS-INT

Severity

Major

Recommended

No

Category

HTTP

Keywords

Webmin Format String Integer Wrap

Release Date

2010/04/05

Update Number

1647

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: Webmin Format String Integer Wrap


This signature detects attempts to exploit a known vulnerability in Webmin. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.

Extended Description

Perl is prone to a format-string vulnerability because it fails to properly handle format specifiers in formatted-printing functions. An attacker may leverage this issue to write to arbitrary process memory, facilitating code execution in the context of the Perl interpreter process. This can result in unauthorized remote access. Developers should treat the formatted-printing functions in Perl as equivalently vulnerable to exploits as the C library versions and should properly sanitize all data passed in the format-specifier argument. All applications that use formatted-printing functions in an unsafe manner should be considered exploitable.

Affected Products

  • Apple mac_os_x 10.3.9
  • Apple mac_os_x 10.4.8
  • Apple mac_os_x_server 10.3.9
  • Apple mac_os_x_server 10.4.8
  • Conectiva linux 10.0.0
  • Curtis_hawthorne tn3270rg 1.0.0 .0
  • Curtis_hawthorne tn3270rg 1.0.1
  • Curtis_hawthorne tn3270rg 1.1.0 .0
  • Debian linux 3.1.0
  • Debian linux 3.1.0 Alpha
  • Debian linux 3.1.0 Amd64
  • Debian linux 3.1.0 Arm
  • Debian linux 3.1.0 Hppa
  • Debian linux 3.1.0 Ia-32
  • Debian linux 3.1.0 Ia-64
  • Debian linux 3.1.0 M68k
  • Debian linux 3.1.0 Mips
  • Debian linux 3.1.0 Mipsel
  • Debian linux 3.1.0 Ppc
  • Debian linux 3.1.0 S/390
  • Debian linux 3.1.0 Sparc
  • Gentoo linux
  • Hp internet_express 6.3
  • Hp internet_express 6.4
  • Hp tru64 5.1.0 A PK6
  • Hp tru64 5.1.0 A PK6 (BL24)
  • Hp tru64 5.1.0 B-2 PK4
  • Hp tru64 5.1.0 B-2 PK4 (BL25)
  • Hp tru64 5.1.0 B-3
  • Ipcop ipcop 1.4.20
  • Larry_wall perl 5.0.0 03
  • Larry_wall perl 5.0.0 04
  • Larry_wall perl 5.0.0 04 04
  • Larry_wall perl 5.0.0 04 05
  • Larry_wall perl 5.0.0 05
  • Larry_wall perl 5.0.0 05 003
  • Larry_wall perl 5.6.0
  • Larry_wall perl 5.6.1
  • Larry_wall perl 5.8.0
  • Larry_wall perl 5.8.0 .0-88.3
  • Larry_wall perl 5.8.1
  • Larry_wall perl 5.8.3
  • Larry_wall perl 5.8.4
  • Larry_wall perl 5.8.4 -1
  • Larry_wall perl 5.8.4 -2
  • Larry_wall perl 5.8.4 -2.3
  • Larry_wall perl 5.8.4 -3
  • Larry_wall perl 5.8.4 -4
  • Larry_wall perl 5.8.4 -5
  • Larry_wall perl 5.8.5
  • Larry_wall perl 5.8.6
  • Larry_wall perl 5.8.7
  • Larry_wall perl 5.9.2
  • Mandriva corporate_server 2.1.0
  • Mandriva corporate_server 2.1.0 X86 64
  • Mandriva corporate_server 3.0.0
  • Mandriva corporate_server 3.0.0 X86 64
  • Mandriva linux_mandrake 10.1.0
  • Mandriva linux_mandrake 10.1.0 X86 64
  • Mandriva linux_mandrake 10.2.0
  • Mandriva linux_mandrake 10.2.0 X86 64
  • Mandriva linux_mandrake 2006.0.0
  • Mandriva linux_mandrake 2006.0.0 X86 64
  • Mandriva multi_network_firewall 2.0.0
  • Openbsd openbsd 3.7
  • Openbsd openbsd 3.8
  • Openpkg openpkg 2.3.0
  • Openpkg openpkg 2.4.0
  • Openpkg openpkg 2.5.0
  • Openpkg openpkg Current
  • Red_hat desktop 4.0.0
  • Red_hat enterprise_linux_as 4
  • Red_hat enterprise_linux_es 4
  • Red_hat enterprise_linux_ws 4
  • Red_hat fedora Core1
  • Red_hat fedora Core2
  • Red_hat fedora Core3
  • Red_hat fedora Core4
  • Red_hat linux 9.0.0 I386
  • Sun solaris 10 Sparc
  • Sun solaris 10 X86
  • Suse linux_desktop 1.0.0
  • Suse linux_personal 10.0.0 OSS
  • Suse linux_personal 8.2.0
  • Suse linux_personal 9.0.0
  • Suse linux_personal 9.0.0 X86 64
  • Suse linux_personal 9.1.0
  • Suse linux_personal 9.1.0 X86 64
  • Suse linux_personal 9.2.0
  • Suse linux_personal 9.2.0 X86 64
  • Suse linux_personal 9.3.0
  • Suse linux_personal 9.3.0 X86 64
  • Suse linux_professional 10.0.0
  • Suse linux_professional 10.0.0 OSS
  • Suse linux_professional 8.2.0
  • Suse linux_professional 9.0.0
  • Suse linux_professional 9.0.0 X86 64
  • Suse linux_professional 9.1.0
  • Suse linux_professional 9.1.0 X86 64
  • Suse linux_professional 9.2.0
  • Suse linux_professional 9.2.0 X86 64
  • Suse linux_professional 9.3.0
  • Suse linux_professional 9.3.0 X86 64
  • Suse novell_linux_desktop 9.0.0
  • Suse open-enterprise-server 9.0.0
  • Suse suse_linux_enterprise_server 8
  • Suse suse_linux_enterprise_server 9
  • Suse suse_linux_openexchange_server 4.0.0
  • Suse suse_linux_retail_solution 8.0.0
  • Suse suse_linux_school_server_for_i386
  • Suse suse_linux_standard_server 8.0.0
  • Suse unitedlinux 1.0.0
  • Trustix secure_enterprise_linux 2.0.0
  • Trustix secure_linux 2.2.0
  • Trustix secure_linux 3.0.0
  • Ubuntu ubuntu_linux 4.1.0 Ia32
  • Ubuntu ubuntu_linux 4.1.0 Ia64
  • Ubuntu ubuntu_linux 4.1.0 Ppc
  • Ubuntu ubuntu_linux 5.0.0 4 Amd64
  • Ubuntu ubuntu_linux 5.0.0 4 I386
  • Ubuntu ubuntu_linux 5.0.0 4 Powerpc
  • Ubuntu ubuntu_linux 5.10.0 Amd64
  • Ubuntu ubuntu_linux 5.10.0 I386
  • Ubuntu ubuntu_linux 5.10.0 Powerpc
  • Webmin usermin 0.4.0
  • Webmin usermin 0.5.0
  • Webmin usermin 0.6.0
  • Webmin usermin 0.7.0
  • Webmin usermin 0.8.0
  • Webmin usermin 0.9.0
  • Webmin usermin 0.91.0
  • Webmin usermin 0.92.0
  • Webmin usermin 0.93.0
  • Webmin usermin 0.94.0
  • Webmin usermin 0.95.0
  • Webmin usermin 0.96.0
  • Webmin usermin 0.97.0
  • Webmin usermin 0.98.0
  • Webmin usermin 0.99.0
  • Webmin usermin 1.0.0
  • Webmin usermin 1.110.0
  • Webmin usermin 1.120.0
  • Webmin usermin 1.130.0
  • Webmin usermin 1.140.0
  • Webmin usermin 1.150.0
  • Webmin usermin 1.160.0
  • Webmin usermin 1.170.0
  • Webmin webmin 0.1.0
  • Webmin webmin 0.2.0
  • Webmin webmin 0.21.0
  • Webmin webmin 0.22.0
  • Webmin webmin 0.3.0
  • Webmin webmin 0.31.0
  • Webmin webmin 0.4.0
  • Webmin webmin 0.41.0
  • Webmin webmin 0.42.0
  • Webmin webmin 0.5.0
  • Webmin webmin 0.5.0 x
  • Webmin webmin 0.51.0
  • Webmin webmin 0.6.0
  • Webmin webmin 0.7.0
  • Webmin webmin 0.76.0
  • Webmin webmin 0.77.0
  • Webmin webmin 0.78.0
  • Webmin webmin 0.79.0
  • Webmin webmin 0.80.0
  • Webmin webmin 0.8.3
  • Webmin webmin 0.8.4
  • Webmin webmin 0.85.0
  • Webmin webmin 0.8.5 Red Hat
  • Webmin webmin 0.88.0
  • Webmin webmin 0.89.0
  • Webmin webmin 0.91.0
  • Webmin webmin 0.92.0
  • Webmin webmin 0.92.0 -1
  • Webmin webmin 0.93.0
  • Webmin webmin 0.94.0
  • Webmin webmin 0.950.0
  • Webmin webmin 0.960.0
  • Webmin webmin 0.970.0
  • Webmin webmin 0.980.0
  • Webmin webmin 0.990.0
  • Webmin webmin 1.0.0 00
  • Webmin webmin 1.0.0 20
  • Webmin webmin 1.0.0 50
  • Webmin webmin 1.0.0 60
  • Webmin webmin 1.0.0 70
  • Webmin webmin 1.0.0 80
  • Webmin webmin 1.0.0 90
  • Webmin webmin 1.100.0
  • Webmin webmin 1.110.0
  • Webmin webmin 1.121.0
  • Webmin webmin 1.130.0
  • Webmin webmin 1.140.0
  • Webmin webmin 1.150.0
  • Webmin webmin 1.160.0
  • Webmin webmin 1.170.0
  • Webmin webmin 1.180.0
  • Webmin webmin 1.190.0
  • Webmin webmin 1.200.0
  • Webmin webmin 1.210.0
  • Webmin webmin 1.220.0
  • Webmin webmin 1.230.0
  • Webmin webmin 1.240.0

References

  • BugTraq: 15629
  • CVE: CVE-2005-3912

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out