CVE-2005-0202: Medium severity GNU Mailman vulnerability
Directory traversal vulnerability in the truepath function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary files via ".../....///" sequences, which are not properly cleansed by regular expressions that are intended to remove "../" and "./" sequences.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0202?
CVE-2005-0202 is considered a high severity vulnerability as it allows remote attackers to read arbitrary files from the server.
How do I fix CVE-2005-0202?
To fix CVE-2005-0202, upgrade Mailman to version 2.1.6 or later where the vulnerability has been addressed.
What versions of Mailman are affected by CVE-2005-0202?
CVE-2005-0202 affects Mailman versions 2.1 through 2.1.5, including all versions up to 2.1.5.
What type of vulnerability is CVE-2005-0202?
CVE-2005-0202 is a directory traversal vulnerability that allows attackers to access restricted files.
Who can exploit CVE-2005-0202?
CVE-2005-0202 can be exploited by remote attackers who can send specially crafted requests to the vulnerable Mailman server.