Revision Date: | 2008-03-20 | Version: | 644 |
Title: | RHSA-2006:0600: mailman security update (Moderate) |
Description: | Mailman is a program used to help manage email discussion lists.
A flaw was found in the way Mailman handled MIME multipart messages. An attacker could send a carefully crafted MIME multipart email message to a mailing list run by Mailman which caused that particular mailing list to stop working. (CVE-2006-2941)
Several cross-site scripting (XSS) issues were found in Mailman. An attacker could exploit these issues to perform cross-site scripting attacks against the Mailman administrator. (CVE-2006-3636)
Red Hat would like to thank Barry Warsaw for disclosing these vulnerabilities.
Users of Mailman should upgrade to these updated packages, which contain backported patches to correct this issue.
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | CVE-2006-2941 CVE-2006-3636 RHSA-2006:0600 RHSA-2006:0600-01 RHSA-2006:0600-01
|
Platform(s): | Red Hat Enterprise Linux 3 Red Hat Enterprise Linux 4
| Product(s): | |
Definition Synopsis |
Red Hat Enterprise Linux must be installed OR Package Information
Red Hat Enterprise Linux 3 is installed
AND mailman is earlier than 3:2.1.5.1-25.rhel3.7
AND mailman is signed with Red Hat master key
OR Package Information
Red Hat Enterprise Linux 4 is installed
AND mailman is earlier than 3:2.1.5.1-34.rhel4.5
AND mailman is signed with Red Hat master key
|
Definition Synopsis |
Red Hat Enterprise Linux must be installed
OR Package Information
Red Hat Enterprise Linux 4 is installed
AND mailman is earlier than 3:2.1.5.1-34.rhel4.5
AND mailman is signed with Red Hat redhatrelease2 key
|