Mailman: Multiple vulnerabilities — GLSA 200609-12

Mailman has multiple vulnerable that can result in Denial of Service, log file injection and XSS.

Affected packages

net-mail/mailman on all architectures
Affected versions < 2.1.9_rc1
Unaffected versions >= 2.1.9_rc1

Background

Mailman is a Python based mailing list server with an extensive web interface.

Description

Mailman fails to properly handle standards-breaking RFC 2231 formatted headers. Furthermore, Moritz Naumann discovered several XSS vulnerabilities and a log file injection.

Impact

An attacker could exploit these vulnerabilities to cause Mailman to stop processing mails, to inject content into the log file or to execute arbitrary scripts running in the context of the administrator or mailing list user's browser.

Workaround

There is no known workaround at this time.

Resolution

All Mailman users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-mail/mailman-2.1.9_rc1"

References

Release date
September 19, 2006

Latest revision
September 19, 2006: 01

Severity
normal

Exploitable
remote

Bugzilla entries