Article 4NQNH Backdoors in Webmin

Backdoors in Webmin

by
corbet
from LWN.net on (#4NQNH)
Anybody using Webmin, a web-basedsystem-administration tool, will want to update now, as it turns out thatthe system has beenbackdoored for over a year. "At some time in April 2018, theWebmin development build server was exploited and a vulnerability added tothe password_change.cgi script. Because the timestamp on the file was setback, it did not show up in any Git diffs. This was included in the Webmin1.890 release."
External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments