security advisorysecurity issuebug fix
Low: mailman security and bug fix update. Date: Thu, 15 Nov 2007 14:11:49 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for mailman on SL4.x i386/x86_64 Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. Synopsis: Low: mailman security and bug fix update Issue date: 2007-11-15 CVE Names: CVE-2006-4624 A flaw was found in Mailman. A remote attacker could spoof messages in the error log, and possibly trick the administrator into visiting malicious URLs via a carriage return/line feed sequence in the URI. (CVE-2006-4624) As well, these updated packages fix the following bugs: * canceling a subscription on the confirm subscription request page caused mailman to crash. * editing the sender filter caused all spam filter rules to be deleted. * the migrate-fhs script was not included. * the mailman init script returned a zero (success) exit code even when an incorrect command was given. For example, the "mailman foo" command returned a zero exit code. In these updated packages the mailmain init script returns the correct exit codes. SL 4.x SRPMS: mailman-2.1.5.1-34.rhel4.6.src.rpm i386: mailman-2.1.5.1-34.rhel4.6.i386.rpm x86_64: mailman-2.1.5.1-34.rhel4.6.x86_64.rpm -Connie Sieh -Troy Dawson . Mailman release for SL 4.x addresses vulnerabilities and maintenance corrections. Essential for users to update and ensure safety.. mailman fix, scientific linux, security update, bug fixes, remote attack. . Severity: Low. LinuxSecurity.com Team
Nov 15, 2007
•Low
Scientific Linux