Mailman is a program used to help manage email discussion lists.
A flaw was found in the way Mailman handled MIME multipart messages. An attacker could send a carefully crafted MIME multipart email message to a mailing list run by Mailman which caused that particular mailing list to stop working. (CVE-2006-2941)
Several cross-site scripting (XSS) issues were found in Mailman. An attacker could exploit these issues to perform cross-site scripting attacks against the Mailman administrator. (CVE-2006-3636)
Red Hat would like to thank Barry Warsaw for disclosing these vulnerabilities.
Users of Mailman should upgrade to these updated packages, which contain backported patches to correct this issue.