RHSA-2011:0307-01 -- Redhat mailmanID: oval:org.secpod.oval:def:500142 | Date: (C)2012-01-31 (M)2023-02-20 |
Class: PATCH | Family: unix |
Mailman is a program used to help manage email discussion lists. Multiple input sanitization flaws were found in the way Mailman displayed usernames of subscribed users on certain pages. If a user who is subscribed to a mailing list were able to trick a victim into visiting one of those pages, they could perform a cross-site scripting attack against the victim. Multiple input sanitization flaws were found in the way Mailman displayed mailing list information. A mailing list administrator could use this flaw to conduct a cross-site scripting attack against victims viewing a list"s "listinfo" page. Red Hat would like to thank Mark Sapiro for reporting the CVE-2011-0707 and CVE-2010-3089 issues. Users of mailman should upgrade to this updated package, which contains backported patches to correct these issues.
Platform: |
Red Hat Enterprise Linux 5 |
Red Hat Enterprise Linux 4 |