CVE-2001-0884: Medium severity GNU Mailman vulnerability
Published Dec 21, 2001
·Updated
Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive information or authentication credentials via a malicious link that is accessed by other web users.
Affected Software
5 affected components
GNU Mailman
GNU Mailman=5.0
GNU Mailman=5.1
GNU Mailman=6.0
GNU Mailman=7.0
Remediation
Patch Available
Patch Available
Event History
Dec 21, 2001
CVE Published
05:00 AM
Jun 25, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0884?
CVE-2001-0884 has a medium severity due to its potential to expose sensitive information via cross-site scripting.
2
How do I fix CVE-2001-0884?
To fix CVE-2001-0884, upgrade Mailman to version 2.08 or later.
3
What versions of Mailman are affected by CVE-2001-0884?
CVE-2001-0884 affects Mailman versions prior to 2.08, specifically 5.0, 5.1, 6.0, and 7.0.
4
What type of vulnerability is CVE-2001-0884?
CVE-2001-0884 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2001-0884 allow an attacker to steal authentication credentials?
Yes, attackers can potentially steal authentication credentials through a crafted link exploiting CVE-2001-0884.