Описание
Security update for mailman
This update for mailman fixes the following issues:
- Fixed a XSS vulnerability and information leak in user options CGI, which could be used to execute arbitrary scripts in the user's browser via specially encoded URLs (bsc#1077358 CVE-2018-5950)
- Fixed a directory traversal vulnerability in MTA transports when using the recommended Mailman Transport for Exim (bsc#925502 CVE-2015-2775)
- Fixed a XSS vulnerability, which allowed malicious listowners to inject scripts into the listinfo pages (bsc#1099510 CVE-2018-0618)
- Fixed arbitrary text injection vulnerability in several mailman CGIs (CVE-2018-13796 bsc#1101288)
- Fixed a CSRF vulnerability on the user options page (CVE-2016-6893 bsc#995352)
Список пакетов
SUSE Linux Enterprise Point of Sale 11 SP3
SUSE Linux Enterprise Server 11 SP3-LTSS
SUSE Linux Enterprise Server 11 SP3-TERADATA
SUSE Linux Enterprise Server 11 SP4
SUSE Linux Enterprise Server for SAP Applications 11 SP4
Ссылки
- Link for SUSE-SU-2019:13924-1
- E-Mail link for SUSE-SU-2019:13924-1
- SUSE Security Ratings
- SUSE Bug 1077358
- SUSE Bug 1099510
- SUSE Bug 1101288
- SUSE Bug 925502
- SUSE Bug 995352
- SUSE CVE CVE-2015-2775 page
- SUSE CVE CVE-2016-6893 page
- SUSE CVE CVE-2018-0618 page
- SUSE CVE CVE-2018-13796 page
- SUSE CVE CVE-2018-5950 page
Описание
Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name.
Затронутые продукты
Ссылки
- CVE-2015-2775
- SUSE Bug 925502
Описание
Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before 2.1.23 allows remote attackers to hijack the authentication of arbitrary users for requests that modify an option, as demonstrated by gaining access to the credentials of a victim's account.
Затронутые продукты
Ссылки
- CVE-2016-6893
- SUSE Bug 995352
- SUSE Bug 997205
Описание
Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
Затронутые продукты
Ссылки
- CVE-2018-0618
- SUSE Bug 1099510
Описание
An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site.
Затронутые продукты
Ссылки
- CVE-2018-13796
- SUSE Bug 1101288
Описание
Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a user-options URL.
Затронутые продукты
Ссылки
- CVE-2018-5950
- SUSE Bug 1077358