[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249982

 
 

909

 
 

195748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2011:0307 -- centos 5 x86_64 mailman

ID: oval:org.secpod.oval:def:200242Date: (C)2012-01-31   (M)2023-02-20
Class: PATCHFamily: unix




Mailman is a program used to help manage email discussion lists. Multiple input sanitization flaws were found in the way Mailman displayed usernames of subscribed users on certain pages. If a user who is subscribed to a mailing list were able to trick a victim into visiting one of those pages, they could perform a cross-site scripting attack against the victim. Multiple input sanitization flaws were found in the way Mailman displayed mailing list information. A mailing list administrator could use this flaw to conduct a cross-site scripting attack against victims viewing a list"s "listinfo" page. Red Hat would like to thank Mark Sapiro for reporting the CVE-2011-0707 and CVE-2010-3089 issues. Users of mailman should upgrade to this updated package, which contains backported patches to correct these issues.

Platform:
CentOS 5
Product:
mailman
Reference:
CESA-2011:0307
CVE-2008-0564
CVE-2010-3089
CVE-2011-0707
CVE    3
CVE-2011-0707
CVE-2008-0564
CVE-2010-3089
CPE    47
cpe:/a:gnu:mailman:2.1.1
cpe:/a:gnu:mailman:2.1.1:beta1
cpe:/a:gnu:mailman:2.0
cpe:/a:gnu:mailman:2.1.13:rc1
...

© SecPod Technologies