First published: Wed Feb 09 2005(Updated: )
Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary files via ".../....///" sequences, which are not properly cleansed by regular expressions that are intended to remove "../" and "./" sequences.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Mailman | =2.1.5 | |
GNU Mailman | =2.1.3 | |
GNU Mailman | =2.1.2 | |
GNU Mailman | =2.1 | |
GNU Mailman | =2.1b1 | |
GNU Mailman | =2.1.1 | |
GNU Mailman | =2.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.