First published: Wed Feb 09 2005(Updated: )
Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary files via ".../....///" sequences, which are not properly cleansed by regular expressions that are intended to remove "../" and "./" sequences.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mailman | =2.1 | |
Mailman | =2.1.1 | |
Mailman | =2.1.2 | |
Mailman | =2.1.3 | |
Mailman | =2.1.4 | |
Mailman | =2.1.5 | |
Mailman | =2.1b1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0202 is considered a high severity vulnerability as it allows remote attackers to read arbitrary files from the server.
To fix CVE-2005-0202, upgrade Mailman to version 2.1.6 or later where the vulnerability has been addressed.
CVE-2005-0202 affects Mailman versions 2.1 through 2.1.5, including all versions up to 2.1.5.
CVE-2005-0202 is a directory traversal vulnerability that allows attackers to access restricted files.
CVE-2005-0202 can be exploited by remote attackers who can send specially crafted requests to the vulnerable Mailman server.