HomeFreeBSD

Update sysutils/usermin to version 1.780.

Description

Update sysutils/usermin to version 1.780.

Contains fix for CVE-2019-15107.

From https://virtualmin.com/node/66890:

To exploit the malicious code, your Webmin installation must have Webmin ->
Webmin Configuration -> Authentication -> Password expiry policy set to
Prompt users with expired passwords to enter a new one. This option is not
set by default, but if it is set, it allows remote code execution.

PR: 239957
Submitted by: Bert JW Regeer <xistence@0x58.com>
Security: CVE-2019-15107

Details

Provenance
olgeniAuthored on
Parents
rP509243: Update sysutils/webmin to version 1.930.
Branches
Unknown
Tags
Unknown