Mailman is a program used to help manage email discussion lists.
A flaw was found in the way Mailman handled MIME multipart messages. An
attacker could send a carefully crafted MIME multipart email message to a
mailing list run by Mailman which caused that particular mailing list
to stop working. (CVE-2006-2941)
Several cross-site scripting (XSS) issues were found in Mailman. An
attacker could exploit these issues to perform cross-site scripting attacks
against the Mailman administrator. (CVE-2006-3636)
Red Hat would like to thank Barry Warsaw for disclosing these vulnerabilities.
Users of Mailman should upgrade to these updated packages, which contain
backported patches to correct this issue.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
RedHat | any | src | mailman | < 2.1.5.1-34.rhel4.5 | mailman-2.1.5.1-34.rhel4.5.src.rpm |
RedHat | any | s390 | mailman | < 2.1.5.1-34.rhel4.5 | mailman-2.1.5.1-34.rhel4.5.s390.rpm |
RedHat | any | x86_64 | mailman | < 2.1.5.1-34.rhel4.5 | mailman-2.1.5.1-34.rhel4.5.x86_64.rpm |
RedHat | any | ia64 | mailman | < 2.1.5.1-34.rhel4.5 | mailman-2.1.5.1-34.rhel4.5.ia64.rpm |
RedHat | any | i386 | mailman | < 2.1.5.1-34.rhel4.5 | mailman-2.1.5.1-34.rhel4.5.i386.rpm |
RedHat | any | ppc | mailman | < 2.1.5.1-34.rhel4.5 | mailman-2.1.5.1-34.rhel4.5.ppc.rpm |
RedHat | any | s390x | mailman | < 2.1.5.1-34.rhel4.5 | mailman-2.1.5.1-34.rhel4.5.s390x.rpm |