[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247974

 
 

909

 
 

194654

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2011:0308-01 -- Redhat mailman

ID: oval:org.secpod.oval:def:500265Date: (C)2012-01-31   (M)2023-02-20
Class: PATCHFamily: unix




Mailman is a program used to help manage email discussion lists. Multiple input sanitization flaws were found in the way Mailman displayed usernames of subscribed users on certain pages. If a user who is subscribed to a mailing list were able to trick a victim into visiting one of those pages, they could perform a cross-site scripting attack against the victim. Multiple input sanitization flaws were found in the way Mailman displayed mailing list information. A mailing list administrator could use this flaw to conduct a cross-site scripting attack against victims viewing a list"s "listinfo" page. Red Hat would like to thank Mark Sapiro for reporting these issues. Users of mailman should upgrade to this updated package, which contains backported patches to correct these issues.

Platform:
Red Hat Enterprise Linux 6
Product:
mailman
Reference:
RHSA-2011:0308-01
CVE-2010-3089
CVE-2011-0707
CVE    2
CVE-2011-0707
CVE-2010-3089
CPE    47
cpe:/a:gnu:mailman:2.1.1
cpe:/a:gnu:mailman:2.1.1:beta1
cpe:/a:gnu:mailman:2.0
cpe:/a:gnu:mailman:2.1.13:rc1
...

© SecPod Technologies