Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-12137

Опубликовано: 24 апр. 2020
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3
CVSS3: 6.1

Описание

GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code.

РелизСтатусПримечание
bionic

released

1:2.1.26-1ubuntu0.1
devel

DNE

eoan

ignored

end of life
esm-apps/focal

released

1:2.1.29-1ubuntu3.1
esm-infra-legacy/trusty

DNE

esm-infra/bionic

released

1:2.1.26-1ubuntu0.1
esm-infra/xenial

released

1:2.1.20-1ubuntu0.4
focal

released

1:2.1.29-1ubuntu3.1
groovy

DNE

hirsute

DNE

Показывать по

4.3 Medium

CVSS2

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
redhat
почти 6 лет назад

GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code.

CVSS3: 6.1
nvd
почти 6 лет назад

GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code.

CVSS3: 6.1
debian
почти 6 лет назад

GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed app ...

suse-cvrf
почти 6 лет назад

Security update for mailman

CVSS3: 6.1
github
больше 3 лет назад

GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code.

4.3 Medium

CVSS2

6.1 Medium

CVSS3