ALT-PU-2021-2340-1
Closed vulnerabilities
BDU:2020-03224
Уязвимость страницы входа в личный архив Cgi/private.py системы управления почтовыми рассылками GNU Mailman, позволяющая нарушителю внедрить произвольный контент
BDU:2020-03997
Уязвимость программного обеспечения для управления рассылками электронных писем Mailman, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю оказать воздействие на целостность данных
Modified: 2024-11-21
CVE-2020-12108
/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00036.html
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00047.html
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00063.html
- https://bugs.launchpad.net/mailman/+bug/1873722
- https://code.launchpad.net/mailman
- https://lists.debian.org/debian-lts-announce/2020/05/msg00007.html
- https://lists.debian.org/debian-lts-announce/2020/07/msg00007.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/74EQIVFB34Q4UYAQLCUWG55YLKAUWCHD/
- https://mail.python.org/pipermail/mailman-announce/
- https://usn.ubuntu.com/4354-1/
- https://www.debian.org/security/2021/dsa-4991
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00036.html
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00047.html
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00063.html
- https://bugs.launchpad.net/mailman/+bug/1873722
- https://code.launchpad.net/mailman
- https://lists.debian.org/debian-lts-announce/2020/05/msg00007.html
- https://lists.debian.org/debian-lts-announce/2020/07/msg00007.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/74EQIVFB34Q4UYAQLCUWG55YLKAUWCHD/
- https://mail.python.org/pipermail/mailman-announce/
- https://usn.ubuntu.com/4354-1/
- https://www.debian.org/security/2021/dsa-4991
Modified: 2024-11-21
CVE-2020-12137
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code.
- http://bazaar.launchpad.net/~mailman-coders/mailman/2.1/view/head:/NEWS
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00047.html
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00063.html
- http://www.openwall.com/lists/oss-security/2020/04/24/3
- https://lists.debian.org/debian-lts-announce/2020/05/msg00002.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6YCMGTTOXXCVM4O6CYZLTZDX6YLYORNF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G4COSBBEMJYLV7WSW5QTUJUOFJFK47KK/
- https://usn.ubuntu.com/4348-1/
- https://www.debian.org/security/2020/dsa-4664
- https://www.openwall.com/lists/oss-security/2020/02/24/2
- https://www.openwall.com/lists/oss-security/2020/02/24/3
- http://bazaar.launchpad.net/~mailman-coders/mailman/2.1/view/head:/NEWS
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00047.html
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00063.html
- http://www.openwall.com/lists/oss-security/2020/04/24/3
- https://lists.debian.org/debian-lts-announce/2020/05/msg00002.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6YCMGTTOXXCVM4O6CYZLTZDX6YLYORNF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G4COSBBEMJYLV7WSW5QTUJUOFJFK47KK/
- https://usn.ubuntu.com/4348-1/
- https://www.debian.org/security/2020/dsa-4664
- https://www.openwall.com/lists/oss-security/2020/02/24/2
- https://www.openwall.com/lists/oss-security/2020/02/24/3
Modified: 2024-11-21
CVE-2020-15011
GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page.
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00047.html
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00063.html
- https://bugs.launchpad.net/mailman/+bug/1877379
- https://lists.debian.org/debian-lts-announce/2020/06/msg00036.html
- https://lists.debian.org/debian-lts-announce/2020/07/msg00007.html
- https://usn.ubuntu.com/4406-1/
- https://www.debian.org/security/2021/dsa-4991
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00047.html
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00063.html
- https://bugs.launchpad.net/mailman/+bug/1877379
- https://lists.debian.org/debian-lts-announce/2020/06/msg00036.html
- https://lists.debian.org/debian-lts-announce/2020/07/msg00007.html
- https://usn.ubuntu.com/4406-1/
- https://www.debian.org/security/2021/dsa-4991
Closed bugs
MAILMAN_SITE_LIST = None breaks initial setup