Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":546,"type":"x","order":1,"pct":78.45,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.31,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.36,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora 31: FEDORA-2020-62f2df3ca4 Critical: Mailman Security Fix

notes=Security fix for CVE-2020-12108. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-62f2df3ca4 2020-07-22 01:19:44.413051 --------------------------------------------------------------------------------Name : mailman Product : Fedora 31 Version : 2.1.34 Release : 1.fc31 URL : https://www.list.org/ Summary : Mailing list manager with built in Web access Description : Mailman is software to help manage email discussion lists, much like Majordomo and Smartmail. Unlike most similar products, Mailman gives each mailing list a webpage, and allows users to subscribe, unsubscribe, etc. over the Web. Even the list manager can administer his or her list entirely from the Web. Mailman also integrates most things people want to do with mailing lists, including archiving, mail news gateways, and so on. Documentation can be found in: /usr/share/doc/mailman When the package has finished installing, you will need to perform some additional installation steps, these are described in: /usr/share/doc/mailman/INSTALL.REDHAT --------------------------------------------------------------------------------Update Information: notes=Security fix for CVE-2020-12108 --------------------------------------------------------------------------------ChangeLog: * Fri Jul 3 2020 Pavel Zhukov - 3:2.1.34-1 - new version v2.1.34 * Mon May 11 2020 Pavel Zhukov - 3:2.1.33-1 - new version v2.1.33 * Wed May 6 2020 Pavel Zhukov - 3:2.1.32-2 - Change mode of /etc/mailman to 2755 (#1656765) * Wed May 6 2020 Pavel Zhukov - 3:2.1.32-1 - New version v2.1.32 --------------------------------------------------------------------------------References: [ 1 ] Bug #1848856 - CVE-2020-12108 mailman: /options/mailman allows Arbitrary Content Injection https://bugzilla.redhat.com/show_bug.cgi?id=1848856 --------------------------------------------------------------------------------This updatecan be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-62f2df3ca4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Mitigating CVE-2020-12108 through an update in RPM Mailman system to bolster email list administration security protocols.. Fedora Mailman Security, Update Notification, Mailing List Management. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 21, 2020 Critical Fedora
172

Ubuntu 18.04 & 16.04: USN-4406-1 Critical Mailman Login Injection

Mailman could be made to inject arbitrary content in the login page if it received a specially crafted input.. =========================================================================Ubuntu Security Notice USN-4406-1 June 29, 2020 mailman vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Mailman could be made to inject arbitrary content in the login page if it received a specially crafted input. Software Description: - mailman: Web-based mailing list manager (legacy branch) Details: It was discovered that Mailman incorrectly handled certain inputs. An attacker could possibly use this issue to inject arbitrary content in the login page. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: mailman 1:2.1.26-1ubuntu0.3 Ubuntu 16.04 LTS: mailman 1:2.1.20-1ubuntu0.6 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4406-1 CVE-2020-15011 Package Information: https://launchpad.net/ubuntu/+source/mailman/1:2.1.26-1ubuntu0.3 https://launchpad.net/ubuntu/+source/mailman/1:2.1.20-1ubuntu0.6 . A recent issue with Mailman on Ubuntu permits unauthorized content insertion during login processes. Swiftly implement updates to fortify your system's security.. mailman security, ubuntu update, content injection, security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 29, 2020 Critical Ubuntu
203

Mageia 6: MGASA-2018-0383 Moderate: Mailman Text Exposure Risk

Updated mailman package fixes security vulnerability: It was discovered that mailman prior to 2.1.29 mishandled URLs in Utils.py:GetPathPieces() which allowed attackers to display arbitrary text on trusted sites (CVE-2018-13796). . MGASA-2018-0383 - Updated mailman packages fix security vulnerability Publication date: 21 Sep 2018 URL: https://advisories.mageia.org/MGASA-2018-0383.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-13796 Updated mailman package fixes security vulnerability: It was discovered that mailman prior to 2.1.29 mishandled URLs in Utils.py:GetPathPieces() which allowed attackers to display arbitrary text on trusted sites (CVE-2018-13796). References: - https://bugs.mageia.org/show_bug.cgi?id=23409 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/QMI7UFFD7ZLOTUTAKJZPPN6H6ME47ECQ/ - https://www.cve.org/CVERecord?id=CVE-2018-13796 SRPMS: - 6/core/mailman-2.1.29-1.mga6 . Revamped mailman modules tackle potential vulnerabilities linked to mishandled links, which may result in unintended text exposure.. mailman security, mageia update, text exposure. . LinuxSecurity.com Team

Calendar 2 Sep 21, 2018 Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":546,"type":"x","order":1,"pct":78.45,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.31,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.36,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here