383
VMScore

CVE-2020-12137

Published: 24/04/2020 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

GNU Mailman 2.x prior to 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu mailman

debian debian linux 9.0

debian debian linux 10.0

fedoraproject fedora 31

fedoraproject fedora 32

debian debian linux 8.0

canonical ubuntu linux 18.04

canonical ubuntu linux 16.04

opensuse leap 15.2

opensuse backports sle 15.0

Vendor Advisories

Synopsis Moderate: mailman:21 security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for the mailman:21 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scori ...
Debian Bug report logs - #958930 mailman: CVE-2020-12137 Package: src:mailman; Maintainer for src:mailman is Mailman for Debian <pkg-mailman-hackers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 26 Apr 2020 19:33:01 UTC Severity: grave Tags: security, upstream Found in ve ...
Several security issues were fixed in Mailman ...
Hanno Boeck discovered that it was possible to create a cross site scripting attack on the webarchives of the Mailman mailing list manager, by sending a special type of attachement For the oldstable distribution (stretch), this problem has been fixed in version 1:2123-1+deb9u5 For the stable distribution (buster), this problem has been fixed in ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: mailman 2x: XSS via file attachments in list archives <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Salvat ...