Jump to content

Advisories MDKSA-2006:165: Updated mailman packages fix multiple vulnerabilities


paul
 Share

Recommended Posts

A flaw was discovered in how Mailman handles MIME multipart messages

where an attacker could send a carefully-crafted MIME multipart

message to a Mailman-run mailing list causing that mailing list to

stop working (CVE-2006-2941).

 

As well, a number of XSS (cross-site scripting) issues were discovered

that could be exploited to perform XSS attacks against the Mailman

administrator (CVE-2006-3636).

 

Finally, a CRLF injection vulnerability allows remote attackers to

spoof messages in the error log (CVE-2006-4624).

 

Updated packages have been patched to address these issues.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...