GNU Mailman Admin Page Multiple Cross-Site Scripting Vulnerabilities
BID:9336
Info
GNU Mailman Admin Page Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 9336 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0965 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 31 2003 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | These issues were announced by the vendor. |
| Vulnerable: |
Redhat Fedora Core1 GNU Mailman 2.1.10 b1 GNU Mailman 2.1.3 GNU Mailman 2.1.1 GNU Mailman 2.1 GNU Mailman 2.0.13 GNU Mailman 2.0.12 GNU Mailman 2.0.11 GNU Mailman 2.0.10 GNU Mailman 2.0.9 GNU Mailman 2.0.8 GNU Mailman 2.0.7 GNU Mailman 2.0.6 GNU Mailman 2.0.5 GNU Mailman 2.0.4 GNU Mailman 2.0.3 GNU Mailman 2.0.2 GNU Mailman 2.0.1 GNU Mailman 2.0 .8 GNU Mailman 2.0 .7 GNU Mailman 2.0 .6 GNU Mailman 2.0 .5 GNU Mailman 2.0 .3 GNU Mailman 2.0 .2 GNU Mailman 2.0 .1 GNU Mailman 2.0 |
| Not Vulnerable: |
GNU Mailman 2.1.4 |
Discussion
GNU Mailman Admin Page Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting vulnerabilities were reported to exist in the administrative pages for GNU Mailman. These issues would likely be exploitable by enticing an administrative user to follow a malicious link with hostile HTML and script code embedded in it.
Exploitation would likely result in theft of administrative cookie-based authentication credentials. Other attacks would also be possible.
Multiple cross-site scripting vulnerabilities were reported to exist in the administrative pages for GNU Mailman. These issues would likely be exploitable by enticing an administrative user to follow a malicious link with hostile HTML and script code embedded in it.
Exploitation would likely result in theft of administrative cookie-based authentication credentials. Other attacks would also be possible.
Exploit / POC
GNU Mailman Admin Page Multiple Cross-Site Scripting Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
GNU Mailman Admin Page Multiple Cross-Site Scripting Vulnerabilities
Solution:
This issue has been addressed in GNU Mailman 2.1.4.
Red Hat has released an advisory (FEDORA-2004-060) and fixes to address these issues in Fedora Linux. Users may apply these fixes using the "up2date" utility. Alternatively Fedora users may apply the fixes manually, fixes are linked below.
RedHat has released an advisory RHSA-2004:020-02 to address these issues. Please see the advisory in web references for more information.
Mandrake has released advisory MDKSA-2004:013 and fixes to address this issue.
Debian has released advisory 436-2 to address these issues. Please see the referenced advisories for more information.
Conectiva has released an advisory (CLA-2004:842) to address this and other issues. Please see the referenced advisory for more information.
Fixes:
Redhat Fedora Core1
GNU Mailman 2.0 .3
GNU Mailman 2.0 .7
GNU Mailman 2.0 .2
GNU Mailman 2.0 .5
GNU Mailman 2.0
GNU Mailman 2.0 .1
GNU Mailman 2.0 .8
GNU Mailman 2.0 .6
GNU Mailman 2.0.1
GNU Mailman 2.0.10
GNU Mailman 2.0.11
GNU Mailman 2.0.12
GNU Mailman 2.0.13
GNU Mailman 2.0.2
GNU Mailman 2.0.3
GNU Mailman 2.0.4
GNU Mailman 2.0.5
GNU Mailman 2.0.6
GNU Mailman 2.0.7
GNU Mailman 2.0.8
GNU Mailman 2.0.9
GNU Mailman 2.1
GNU Mailman 2.1.1
GNU Mailman 2.1.10 b1
GNU Mailman 2.1.3
Solution:
This issue has been addressed in GNU Mailman 2.1.4.
Red Hat has released an advisory (FEDORA-2004-060) and fixes to address these issues in Fedora Linux. Users may apply these fixes using the "up2date" utility. Alternatively Fedora users may apply the fixes manually, fixes are linked below.
RedHat has released an advisory RHSA-2004:020-02 to address these issues. Please see the advisory in web references for more information.
Mandrake has released advisory MDKSA-2004:013 and fixes to address this issue.
Debian has released advisory 436-2 to address these issues. Please see the referenced advisories for more information.
Conectiva has released an advisory (CLA-2004:842) to address this and other issues. Please see the referenced advisory for more information.
Fixes:
Redhat Fedora Core1
-
Fedora mailman-2.1.4-1.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /mailman-2.1.4-1.i386.rpm -
Fedora mailman-debuginfo-2.1.4-1.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /debug/mailman-debuginfo-2.1.4-1.i386.rpm
GNU Mailman 2.0 .3
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.0 .7
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.0 .2
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.0 .5
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.0
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.0 .1
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.0 .8
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.0 .6
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.0.1
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.0.10
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.0.11
-
Debian mailman_2.0.11-1woody8_alpha.deb
http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11- 1woody8_alpha.deb -
Debian mailman_2.0.11-1woody8_arm.deb
http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11- 1woody8_arm.deb -
Debian mailman_2.0.11-1woody8_hppa.deb
http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11- 1woody8_hppa.deb -
Debian mailman_2.0.11-1woody8_i386.deb
http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11- 1woody8_i386.deb -
Debian mailman_2.0.11-1woody8_ia64.deb
http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11- 1woody8_ia64.deb -
Debian mailman_2.0.11-1woody8_m68k.deb
http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11- 1woody8_m68k.deb -
Debian mailman_2.0.11-1woody8_mips.deb
http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11- 1woody8_mips.deb -
Debian mailman_2.0.11-1woody8_powerpc.deb
http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11- 1woody8_powerpc.deb -
Debian mailman_2.0.11-1woody8_s390.deb
http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11- 1woody8_s390.deb -
Debian mailman_2.0.11-1woody8_sparc.deb
http://security.debian.org/pool/updates/main/m/mailman/mailman_2.0.11- 1woody8_sparc.deb -
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.0.12
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.0.13
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103 -
Mandrake mailman-2.0.14-1.1.91mdk.i586.rpm
Mandrake Linux 9.1:
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mailman-2.0.14-1.1.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC:
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mailman-2.0.14-1.1.C21mdk.i586.rpm
Corporate Server 2.1:
http://www.mandrakesecure.net/en/ftp.php
GNU Mailman 2.0.2
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.0.3
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.0.4
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.0.5
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.0.6
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.0.7
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.0.8
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.0.9
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.1
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.1.1
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103 -
Red Hat mailman-2.1.1-5.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/mailman-2.1.1-5.i386.rpm
GNU Mailman 2.1.10 b1
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
GNU Mailman 2.1.3
-
GNU Mailman 2.1.4
http://sourceforge.net/project/showfiles.php?group_id=103
References
GNU Mailman Admin Page Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- Mailman Homepage (GNU)
- Mailman Release Name: 2.1.4 (GNU)
- RHSA-2004:020-02 - mailman (RedHat)