Usermin security vulnerabilities in Unix and Linux management platforms

Source: Internet
Author: User
[Saidi Net News] Usermin is a widely used management platform in Unix and Linux. In September 14, according to some security researchers, a vulnerability was found on this platform, it enables hackers to run malicious code through specially crafted emails.

Usermin enables Unix and Linux users to manage their accounts on the network through Web interfaces, such as reading emails. This tool is generally not included in Unix or Linux products, but often used with Webmin. Webmin is one of the most popular system management tools released together with Linux products such as Suse, Mandrake, and Gentoo. Some researchers said that this independent vulnerability, although not very serious, has an impact on both Webmin and Usermin.

This vulnerability exists in Usermin's email function. It allows hackers to insert malicious code into specially crafted emails and allow remote execution of the Code.

According to ThomasKristensen, chief technology officer of Secunia, the Danish Security Company, "some emails cannot be correctly verified when using Usermin and can be exploited by sending malicious emails to Usermin users ." Secunia rated the vulnerability as "high-risk" level, that is, level 2.

You are advised to upgrade to the latest Usermin and Webmin versions.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.