First published: Wed Apr 29 2020(Updated: )
It was discovered that Mailman incorrectly handled certain inputs. An attacker could possibly use this to issue execute arbitrary scripts or HTML. (CVE-2018-0618) It was discovered that Mailman incorrectly handled certain inputs. An attacker could possibly use this issue to display arbitrary text on a web page. (CVE-2018-13796) It was discovered that Mailman incorrectly handled certain files. An attacker could possibly use this issue to execute arbitrary code. (CVE-2020-12137)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/mailman | <1:2.1.26-1ubuntu0.1 | 1:2.1.26-1ubuntu0.1 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/mailman | <1:2.1.20-1ubuntu0.4 | 1:2.1.20-1ubuntu0.4 |
Ubuntu Linux | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The vulnerability ID for the Mailman vulnerabilities is CVE-2018-0618.
The Mailman vulnerabilities could allow an attacker to execute arbitrary scripts or HTML or display arbitrary text.
Mailman versions 2.1.26-1ubuntu0.1 (Ubuntu 18.04) and 2.1.20-1ubuntu0.4 (Ubuntu 16.04) are affected by the vulnerabilities.
To fix the Mailman vulnerabilities, update to version 1:2.1.26-1ubuntu0.1 (Ubuntu 18.04) or version 1:2.1.20-1ubuntu0.4 (Ubuntu 16.04).
You can find more information about the Mailman vulnerabilities at the following references: [CVE-2018-0618](https://ubuntu.com/security/CVE-2018-0618), [CVE-2018-13796](https://ubuntu.com/security/CVE-2018-13796), [CVE-2020-12137](https://ubuntu.com/security/CVE-2020-12137).