[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

251782

 
 

909

 
 

196543

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2019:13924-1 -- SLES mailman

ID: oval:org.secpod.oval:def:89003352Date: (C)2021-02-27   (M)2022-10-10
Class: PATCHFamily: unix




This update for mailman fixes the following issues: - Fixed a XSS vulnerability and information leak in user options CGI, which could be used to execute arbitrary scripts in the user"s browser via specially encoded URLs - Fixed a directory traversal vulnerability in MTA transports when using the recommended Mailman Transport for Exim - Fixed a XSS vulnerability, which allowed malicious listowners to inject scripts into the listinfo pages - Fixed arbitrary text injection vulnerability in several mailman CGIs - Fixed a CSRF vulnerability on the user options page

Platform:
SUSE Linux Enterprise Server 11 SP4
Product:
mailman
Reference:
SUSE-SU-2019:13924-1
CVE-2015-2775
CVE-2016-6893
CVE-2018-0618
CVE-2018-13796
CVE-2018-5950
CVE    5
CVE-2016-6893
CVE-2018-0618
CVE-2018-13796
CVE-2018-5950
...
CPE    48
cpe:/a:gnu:mailman:2.1.12:rc2
cpe:/a:gnu:mailman:2.1.12:rc1
cpe:/a:gnu:mailman:2.1.1
cpe:/a:gnu:mailman:2.1.13:rc1
...

© SecPod Technologies