Lucene search

K
centosCentOS ProjectCESA-2018:0504
HistoryMar 14, 2018 - 2:47 p.m.

mailman security update

2018-03-1414:47:13
CentOS Project
lists.centos.org
52

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.002

Percentile

64.8%

CentOS Errata and Security Advisory CESA-2018:0504

Mailman is a program used to help manage e-mail discussion lists.

Security Fix(es):

  • mailman: Cross-site scripting (XSS) vulnerability in web UI (CVE-2018-5950)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2018-March/084956.html

Affected packages:
mailman

Upstream details at:
https://access.redhat.com/errata/RHSA-2018:0504

OSVersionArchitecturePackageVersionFilename
CentOS6i686mailman< 2.1.12-26.el6_9.3mailman-2.1.12-26.el6_9.3.i686.rpm
CentOS6x86_64mailman< 2.1.12-26.el6_9.3mailman-2.1.12-26.el6_9.3.x86_64.rpm

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.002

Percentile

64.8%