First published: Wed Sep 06 2006(Updated: )
Mailman is a program used to help manage email discussion lists.<br>A flaw was found in the way Mailman handled MIME multipart messages. An<br>attacker could send a carefully crafted MIME multipart email message to a<br>mailing list run by Mailman which caused that particular mailing list<br>to stop working. (CVE-2006-2941)<br>Several cross-site scripting (XSS) issues were found in Mailman. An<br>attacker could exploit these issues to perform cross-site scripting attacks<br>against the Mailman administrator. (CVE-2006-3636)<br>Red Hat would like to thank Barry Warsaw for disclosing these vulnerabilities.<br>Users of Mailman should upgrade to these updated packages, which contain<br>backported patches to correct this issue.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/mailman | <2.1.5.1-34.rhel4.5 | 2.1.5.1-34.rhel4.5 |
redhat/mailman | <2.1.5.1-34.rhel4.5 | 2.1.5.1-34.rhel4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2006:0600 is classified as moderate.
To fix RHSA-2006:0600, you should update the Mailman package to version 2.1.5.1-34.rhel4.5.
RHSA-2006:0600 affects Mailman version prior to 2.1.5.1-34.rhel4.5.
RHSA-2006:0600 addresses a vulnerability in how Mailman handles MIME multipart messages.
The advisory for RHSA-2006:0600 was published by Red Hat.