The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote attackers to conduct a brute force attack to guess user IDs and passwords.
| Software | From | Fixed in |
|---|---|---|
| usermin / usermin | 1.070 | 1.070.x |
| webmin / webmin | 1.1.40 | 1.1.40.x |
| debian / debian_linux | 3.0 | 3.0.x |