CVE-2005-3042

Publication date 22 September 2005

Last updated 17 July 2025


Ubuntu priority

Description

miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when "full PAM conversations" is enabled, allows remote attackers to bypass authentication by spoofing session IDs via certain metacharacters (line feed or carriage return).

Status



Access our resources on patching vulnerabilities