Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Gentoo: GLSA 200502-11 Normal: Mailman Directory Traversal Threat

gentoo
Calendar Grey February 10, 2005
Scroller Gentoo
Gentoo Security Notice GLSA 202115-05: Mailman poses a directory traversal risk, potentially exposing sensitive information. Immediate upgrade is recommended.
Mailman fails to properly sanitize input, leading to information disclosure.

Summary

Gentoo Linux Security Advisory GLSA 200502-11 https://security.gentoo.org/ Severity: Normal Title: Mailman: Directory traversal vulnerability Date: February 10, 2005 Bugs: #81109 ID: 200502-11

Synopsis ======= Mailman fails to properly sanitize input, leading to information disclosure.
Background ========= Mailman is a Python-based mailing list server with an extensive web interface.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-mail/mailman < 2.1.5-r4 >= 2.1.5-r4
========== Mailman contains an error in private.py which fails to properly sanitize input paths.
Impact ===== An attacker could exploit this flaw to obtain arbitrary files on the web server.
W...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround