Lucene search

K
debianDebianDEBIAN:DLA-186-1:C26AA
HistoryApr 06, 2015 - 5:13 p.m.

[SECURITY] [DLA 186-1] mailman security update

2015-04-0617:13:43
lists.debian.org
13

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

6.1

Confidence

High

EPSS

0.031

Percentile

91.0%

Package : mailman
Version : 1:2.1.13-6
CVE ID : CVE-2015-2775
Debian Bug : 781626

A path traversal vulnerability was discovered in Mailman, the mailing
list manager. Installations using a transport script (such as
postfix-to-mailman.py) to interface with their MTA instead of static
aliases were vulnerable to a path traversal attack. To successfully
exploit this, an attacker needs write access on the local file system.

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

6.1

Confidence

High

EPSS

0.031

Percentile

91.0%