Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Mageia 6: MGASA-2018-0383 Moderate: Mailman Text Exposure Risk

mageia
Calendar Grey September 21, 2018
Dist Mageia Esm H88
Revamped mailman modules tackle potential vulnerabilities linked to mishandled links, which may result in unintended text exposure.
Updated mailman package fixes security vulnerability: It was discovered that mailman prior to 2.1.29 mishandled URLs in Utils.py:GetPathPieces() which allowed attackers to display...

Summary

Updated mailman package fixes security vulnerability:
It was discovered that mailman prior to 2.1.29 mishandled URLs in Utils.py:GetPathPieces() which allowed attackers to display arbitrary text on trusted sites (CVE-2018-13796).

References

- https://bugs.mageia.org/show_bug.cgi?id=23409

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/QMI7UFFD7ZLOTUTAKJZPPN6H6ME47ECQ/

- https://www.cve.org/CVERecord?id=CVE-2018-13796

Resolution

SRPMS

- 6/core/mailman-2.1.29-1.mga6

Publication date: 21 Sep 2018
URL: https://advisories.mageia.org/MGASA-2018-0383.html
Type: security
CVE: CVE-2018-13796

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here