Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Gentoo: 202401-12 Moderate: mailman Open Redirect Exploit

gentoo
Calendar Grey February 17, 2003
Dist Gentoo Esm H88
Gentoo Notification: mailman encounters severe remote XSS vulnerabilities; ensure you upgrade to version 2.1.1 to mitigate these issues.
The email variable and the default error page in mailmain 2.1 contains cross site scripting vulnerabilities.

Summary


- ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200302-05
- ---------------------------------------------------------------------
DATE    : 2003-02-17 09:16 UTC

- ---------------------------------------------------------------------
The email variable and the default error page in mailmain 2.1 contains cross site scripting vulnerabilities.
Read the full advisory at: http://marc.theaimsgroup.com/?l=bugtraq&m=104342745916111&w=2
SOLUTION
It is recommended that all Gentoo Linux users who are running net-mail/mailman upgrade to mailman-2.1.1 as follows:
emerge sync emerge -u mailman emerge clean
- --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at - ---------------------------------------------------------------------

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

PACKAGE : mailman
SUMMARY : cross site scripting
EXPLOIT : remote

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here