First published: Tue Mar 01 2011(Updated: )
Mailman is a program used to help manage email discussion lists.<br>Multiple input sanitization flaws were found in the way Mailman displayed<br>usernames of subscribed users on certain pages. If a user who is subscribed<br>to a mailing list were able to trick a victim into visiting one of those<br>pages, they could perform a cross-site scripting (XSS) attack against the<br>victim. (CVE-2011-0707)<br>Multiple input sanitization flaws were found in the way Mailman displayed<br>mailing list information. A mailing list administrator could use this flaw<br>to conduct a cross-site scripting (XSS) attack against victims viewing a<br>list's "listinfo" page. (CVE-2008-0564, CVE-2010-3089)<br>Red Hat would like to thank Mark Sapiro for reporting the CVE-2011-0707 and<br>CVE-2010-3089 issues.<br>Users of mailman should upgrade to this updated package, which contains<br>backported patches to correct these issues.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/mailman | <2.1.9-6.el5_6.1 | 2.1.9-6.el5_6.1 |
redhat/mailman | <2.1.9-6.el5_6.1 | 2.1.9-6.el5_6.1 |
redhat/mailman | <2.1.5.1-34.rhel4.7 | 2.1.5.1-34.rhel4.7 |
redhat/mailman | <2.1.5.1-34.rhel4.7 | 2.1.5.1-34.rhel4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.