Login
Newsletter
Werbung

Sicherheit: Mangelnde Eingabeprüfung in Mailman
Aktuelle Meldungen Distributionen
Name: Mangelnde Eingabeprüfung in Mailman
ID: USN-4406-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS, Ubuntu 18.04 LTS
Datum: Di, 30. Juni 2020, 00:15
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15011
Applikationen: MailMan

Originalnachricht


--===============8419082141677179752==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="BwCQnh7xodEAoBMC"
Content-Disposition: inline


--BwCQnh7xodEAoBMC
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-4406-1
June 29, 2020

mailman vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Mailman could be made to inject arbitrary content in the login page if it
received a specially crafted input.

Software Description:
- mailman: Web-based mailing list manager (legacy branch)

Details:

It was discovered that Mailman incorrectly handled certain inputs.
An attacker could possibly use this issue to inject arbitrary content
in the login page.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
mailman 1:2.1.26-1ubuntu0.3

Ubuntu 16.04 LTS:
mailman 1:2.1.20-1ubuntu0.6

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4406-1
CVE-2020-15011

Package Information:
https://launchpad.net/ubuntu/+source/mailman/1:2.1.26-1ubuntu0.3
https://launchpad.net/ubuntu/+source/mailman/1:2.1.20-1ubuntu0.6

--BwCQnh7xodEAoBMC
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEf+ebRFcoyOoAQoOeRbznW4QLH2kFAl75/6UACgkQRbznW4QL
H2nZcQ/+LWxYoit0iWdgkYfp9bpm+b7cB6Uo9JfdRoyv9UlKW0xXWANDD9COLqYj
IkH/RDkDPkBpevMzJycm+9W7FwtJvkVnPh3hMnl5Ud61CSUAhrZg+InSolKJ3SwB
14aXfGJIoni9WizDWSQeO08Zd3jo7gS8Sb92c35DTIHBWivsNk5WMOiWUceYKCFR
OUVBzT+LUNI3yt9lqKXUYKDFBvCAyOz84V290cZKtv1PIcQJImn7ohsaJFttrG5i
xIn0yIjsBdOh4mePbngiX0ic3+XC13zlpHcKYzt8pDkEETZo7A3VE+GOv+Tn5CQa
dfItmqnpkUXKjx3V2ORS1cHxfrOul1kEWxZVcT5QLysK1VVrDSs46dRFoiIJRzlc
OQ5WwLaxMgWztbGNGfBlfmbSc0o3+KBeLY8DxZwEcTPIvCkwHIsHZF6O431WDrIz
WcOFclN0n0QM6tBflnnKy6Sg2SU4SAwSkVt4AK5yNpA5vQq3nKY3qNxPyg+Px6VX
willTxKqzWChjXWf5qmktWOEu7fMqe2vgA+/EuhHqnDiBgI0hoTvqw5sn3wymVET
T/zPtZxgDIWTxK/G1qq3TbEciL6Aa2K89ih+55F980NA+sVJLE8usKfbiaU4IT7R
7aEFFsCKPGUScwawq4gZKq4x+zE1JwXk5r7zry+SBvD0ftvke4I=
=qAg7
-----END PGP SIGNATURE-----

--BwCQnh7xodEAoBMC--


--===============8419082141677179752==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung