Oval Definition:oval:com.redhat.rhsa:def:20060600
Revision Date:2008-03-20Version:644
Title:RHSA-2006:0600: mailman security update (Moderate)
Description:Mailman is a program used to help manage email discussion lists.

  • A flaw was found in the way Mailman handled MIME multipart messages. An attacker could send a carefully crafted MIME multipart email message to a mailing list run by Mailman which caused that particular mailing list to stop working. (CVE-2006-2941)

  • Several cross-site scripting (XSS) issues were found in Mailman. An attacker could exploit these issues to perform cross-site scripting attacks against the Mailman administrator. (CVE-2006-3636)

    Red Hat would like to thank Barry Warsaw for disclosing these vulnerabilities.

    Users of Mailman should upgrade to these updated packages, which contain backported patches to correct this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2006-2941
    CVE-2006-3636
    RHSA-2006:0600
    RHSA-2006:0600-01
    RHSA-2006:0600-01
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND mailman is earlier than 3:2.1.5.1-25.rhel3.7
  • AND mailman is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND mailman is earlier than 3:2.1.5.1-34.rhel4.5
  • AND mailman is signed with Red Hat master key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND mailman is earlier than 3:2.1.5.1-34.rhel4.5
  • AND mailman is signed with Red Hat redhatrelease2 key
  • BACK