DSA-2170-1 mailman -- several vulnerabilities

Related Vulnerabilities: CVE-2010-3089   CVE-2011-0707  

Two cross site scripting vulnerabilities were been discovered in Mailman, a web-based mailing list manager. These allowed an attacker to retrieve session cookies via inserting crafted JavaScript into confirmation messages (CVE-2011-0707) and in the list admin interface (CVE-2010-3089; oldstable only). For the oldstable distribution (lenny), these problems have been fixed in version 1:2.1.11-11+lenny2. For the stable distribution (squeeze), this problem has been fixed in version 1:2.1.13-5. For the testing (wheezy) and unstable distribution (sid), this problem has been fixed in version 1:2.1.14-1. We recommend that you upgrade your mailman packages.

Debian Security Advisory

DSA-2170-1 mailman -- several vulnerabilities

Date Reported:
18 Feb 2011
Affected Packages:
mailman
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2010-3089, CVE-2011-0707.
More information:

Two cross site scripting vulnerabilities were been discovered in Mailman, a web-based mailing list manager. These allowed an attacker to retrieve session cookies via inserting crafted JavaScript into confirmation messages (CVE-2011-0707) and in the list admin interface (CVE-2010-3089; oldstable only).

For the oldstable distribution (lenny), these problems have been fixed in version 1:2.1.11-11+lenny2.

For the stable distribution (squeeze), this problem has been fixed in version 1:2.1.13-5.

For the testing (wheezy) and unstable distribution (sid), this problem has been fixed in version 1:2.1.14-1.

We recommend that you upgrade your mailman packages.