Webmin 0.92, when installed from an RPM, creates /var/webmin with insecure permissions (world readable), which could allow local users to read the root user's cookie-based authentication credentials and possibly hijack the root user's session using the credentials.
Link | Tags |
---|---|
http://www.webmin.com/changes.html | |
http://www.securityfocus.com/bid/4328 | vdb entry patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/8595 | vdb entry |
http://online.securityfocus.com/archive/1/263181 | mailing list |