Bug 13419 - webmin new security issues fixed upstream in 1.690
Summary: webmin new security issues fixed upstream in 1.690
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 4
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/600092/
Whiteboard: MGA3TOO MGA3-32-OK MGA3-64-OK MGA4-32...
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2014-05-21 18:02 CEST by David Walser
Modified: 2014-05-23 17:08 CEST (History)
3 users (show)

See Also:
Source RPM: webmin-1.680-1.mga4.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2014-05-21 18:02:27 CEST
Upstream has released version 1.680 today (May 21).

The official release announcement and changelog hasn't been posted yet.

Looking at the git commit log, it looks like there are fixes for multiple XSS issues, and another security issue in the cron module when specifying an invalid user.  I'll post an advisory once the upstream changelog is available.

Git commit log:
https://github.com/webmin/webmin/commits/master

Upstream changelog page:
http://www.webmin.com/changes.html

Updated packages in core/updates_testing:
========================
webmin-1.690-1.mga3
webmin-1.690-1.mga4

from SRPMS:
webmin-1.690-1.mga3.src.rpm
webmin-1.690-1.mga4.src.rpm

Reproducible: 

Steps to Reproduce:
David Walser 2014-05-21 18:02:33 CEST

Whiteboard: (none) => MGA3TOO

Comment 1 David Walser 2014-05-22 15:37:55 CEST
Advisory:
========================

Updated webmin package fix security vulnerabilities:

Webmin has been updated to version 1.690, which fixes a security issue in the
cron module and several XSS issues in pop-up windows.

References:
http://www.webmin.com/changes.html
Comment 2 William Kenney 2014-05-22 18:24:29 CEST
In VirtualBox, M3, KDE, 32-bit

Package(s) under test:
webmin

default install of webmin

[root@localhost wilcal]# urpmi webmin
Package webmin-1.680-1.mga3.noarch is already installed

webmin works, I can use the functions that I often use.
I can access webmin from another workstation on the LAN.

install webmin from updates_testing

Stop and restart webmin.

[root@localhost wilcal]# urpmi webmin
Package webmin-1.690-1.mga3.noarch is already installed

webmin works, I can use the functions that I often use.
I can access webmin from another workstation on the LAN.

Test platform:
Intel Core i7-2600K Sandy Bridge 3.4GHz
GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo
GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB
RTL8111/8168B PCI Express 1Gbit Ethernet
DRAM 16GB (4 x 4GB)
Mageia 4 64-bit, Nvidia driver
virtualbox-4.3.10-1.1.mga4.x86_64
virtualbox-guest-additions-4.3.10-1.1.mga4.x86_64

CC: (none) => wilcal.int

Comment 3 William Kenney 2014-05-22 18:24:50 CEST
In VirtualBox, M3, KDE, 64-bit

Package(s) under test:
webmin

default install of webmin

[root@localhost wilcal]# urpmi webmin
Package webmin-1.680-1.mga3.noarch is already installed

webmin works, I can use the functions that I often use.
I can access webmin from another workstation on the LAN.

install webmin from updates_testing

Stop and restart webmin.

[root@localhost wilcal]# urpmi webmin
Package webmin-1.690-1.mga3.noarch is already installed

webmin works, I can use the functions that I often use.
I can access webmin from another workstation on the LAN.

Test platform:
Intel Core i7-2600K Sandy Bridge 3.4GHz
GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo
GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB
RTL8111/8168B PCI Express 1Gbit Ethernet
DRAM 16GB (4 x 4GB)
Mageia 4 64-bit, Nvidia driver
virtualbox-4.3.10-1.1.mga4.x86_64
virtualbox-guest-additions-4.3.10-1.1.mga4.x86_64
Comment 4 William Kenney 2014-05-22 18:25:13 CEST
In VirtualBox, M4, KDE, 32-bit

Package(s) under test:
webmin

default install of webmin

[root@localhost wilcal]# urpmi webmin
Package webmin-1.680-1.mga4.noarch is already installed

webmin works, I can use the functions that I often use.
I can access webmin from another workstation on the LAN.

install webmin from updates_testing

Stop and restart webmin.

[root@localhost wilcal]# urpmi webmin
Package webmin-1.690-1.mga4.noarch is already installed

webmin works, I can use the functions that I often use.
I can access webmin from another workstation on the LAN.

Test platform:
Intel Core i7-2600K Sandy Bridge 3.4GHz
GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo
GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB
RTL8111/8168B PCI Express 1Gbit Ethernet
DRAM 16GB (4 x 4GB)
Mageia 4 64-bit, Nvidia driver
virtualbox-4.3.10-1.1.mga4.x86_64
virtualbox-guest-additions-4.3.10-1.1.mga4.x86_64
Comment 5 William Kenney 2014-05-22 18:25:33 CEST
In VirtualBox, M4, KDE, 64-bit

Package(s) under test:
webmin

default install of webmin

[root@localhost wilcal]# urpmi webmin
Package webmin-1.680-1.mga4.noarch is already installed

webmin works, I can use the functions that I often use.
I can access webmin from another workstation on the LAN.

install webmin from updates_testing

Stop and restart webmin.

[root@localhost wilcal]# urpmi webmin
Package webmin-1.690-1.mga4.noarch is already installed

webmin works, I can use the functions that I often use.
I can access webmin from another workstation on the LAN.

Test platform:
Intel Core i7-2600K Sandy Bridge 3.4GHz
GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo
GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB
RTL8111/8168B PCI Express 1Gbit Ethernet
DRAM 16GB (4 x 4GB)
Mageia 4 64-bit, Nvidia driver
virtualbox-4.3.10-1.1.mga4.x86_64
virtualbox-guest-additions-4.3.10-1.1.mga4.x86_64
William Kenney 2014-05-22 18:26:32 CEST

Whiteboard: MGA3TOO => MGA3TOO MGA3-32-OK MGA3-64-OK MGA4-32-OK MGA4-64-OK

Comment 6 William Kenney 2014-05-22 18:27:11 CEST
For me this update works fine.
Testing complete for mga3 32-bit & 64-bit
Testing complete for mga4 32-bit & 64-bit
Validating the update.
Could someone from the sysadmin team push this to updates.
Thanks

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 7 Thomas Backlund 2014-05-22 19:31:23 CEST
advisory added.

Update pushed:
http://advisories.mageia.org/MGASA-2014-0233.html

Status: NEW => RESOLVED
CC: (none) => tmb
Resolution: (none) => FIXED
Whiteboard: MGA3TOO MGA3-32-OK MGA3-64-OK MGA4-32-OK MGA4-64-OK => MGA3TOO MGA3-32-OK MGA3-64-OK MGA4-32-OK MGA4-64-OK advisory

David Walser 2014-05-23 17:08:14 CEST

URL: (none) => http://lwn.net/Vulnerabilities/600092/


Note You need to log in before you can comment on or make changes to this bug.