Menu

#5550 Procmail-Wrapper Security Alert Need More Clarification

1.990
open
nobody
None
5
2022-03-06
2022-03-04
Eric
No

Hi,

Can you please elaborate where to check this version if we installed Virtuamin via RPM manually from here

https://download.webmin.com/download/virtualmin/wbm-virtual-server-6.17.gpl-1.noarch.rpm

Virtualmin Procmail wrapper version 1.0 - Privilege escalation exploit.
Version 1.0 of the procmail-wrapper package installed with Virtualmin has a vulnerability that can be used by anyone with SSH access to gain root privileges. To prevent this, all Virtualmin users should upgrade to version 1.1 or later immediately.

We do see these 2 files from the install?

/usr/libexec/webmin/virtual-server/procmail-wrapper
/usr/libexec/webmin/virtual-server/procmail-wrapper.c

How do we check what or if procmail-wrapper is installed we happen to use sendmail instead of postfix if that matters?

Thanks

Eric

Related

Bugs: #5550

Discussion

  • Jamie Cameron

    Jamie Cameron - 2022-03-05

    There's a separate procmail-wrapper package that you need to update for this fix.

     
    • Eric

      Eric - 2022-03-05

      Hi,

      Ok but where is the link to download the updated package?

      We did not use virtulamin repo we installed RPM off link below using local
      yum install?

      Thank You,

      From: Jamie Cameron [mailto:jcameron@users.sourceforge.net]
      Sent: Friday, March 04, 2022 5:54 PM
      To: [webadmin:bugs]
      Subject: [webadmin:bugs] #5550 Procmail-Wrapper Security Alert Need More
      Clarification

      There's a separate procmail-wrapper package that you need to update for this
      fix.


      [bugs:#5550] https://sourceforge.net/p/webadmin/bugs/5550/
      Procmail-Wrapper Security Alert Need More Clarification

      Status: open
      Group: 1.990
      Created: Fri Mar 04, 2022 05:24 PM UTC by Eric
      Last Updated: Fri Mar 04, 2022 05:24 PM UTC
      Owner: nobody

      Hi,

      Can you please elaborate where to check this version if we installed
      Virtuamin via RPM manually from here

      https://download.webmin.com/download/virtualmin/wbm-virtual-server-6.17.gpl-
      1.noarch.rpm

      Virtualmin Procmail wrapper version 1.0 - Privilege escalation exploit.
      Version 1.0 of the procmail-wrapper package installed with Virtualmin has a
      vulnerability that can be used by anyone with SSH access to gain root
      privileges. To prevent this, all Virtualmin users should upgrade to version
      1.1 or later immediately.

      We do see these 2 files from the install?

      /usr/libexec/webmin/virtual-server/procmail-wrapper
      /usr/libexec/webmin/virtual-server/procmail-wrapper.c

      How do we check what or if procmail-wrapper is installed we happen to use
      sendmail instead of postfix if that matters?

      Thanks

      Eric


      Sent from sourceforge.net because you indicated interest in
      https://sourceforge.net/p/webadmin/bugs/5550/

      To unsubscribe from further messages, please visit
      https://sourceforge.net/auth/subscriptions/

       

      Related

      Bugs: #5550

  • Jamie Cameron

    Jamie Cameron - 2022-03-05

    Do you have the /usr/bin/procmail-wrapper command on your system?

     
  • Eric

    Eric - 2022-03-05

    Hi,

    No we do not is this because we use sendmail and not postfix? Since sendmail has its own wrapper to procmail?

    I apologize for this bug request it just was not clear on your security alert about this particular package on what systems it may or may not be installed on etc.

    Thank You,

    Eric

     
    • Jamie Cameron

      Jamie Cameron - 2022-03-06

      Yes, this is only an issue for Postfix users who installed using the full Virtualmin installer.

       

Log in to post a comment.

Auth0 Logo