Mandrake advisory for webmin

20

Author: JT Smith

LinuxSecurity.com: “Recently, Caldera found that when webmin starts a system daemon from
the web frontend it does not clear its environment variables. Since
these variables contain the authorization of the administrator, any
daemon would also get these variables.”

Category:

  • Linux