QID 198576

Date Published: 2021-11-23

QID 198576: Ubuntu Security Notification for Mailman Vulnerabilities (USN-5121-2)

Mailman is a Web-based mailing list manager.This update provides the corresponding updates for Ubuntu 20.04 LTS(Focal)

Focal is prone to:
CVE-2020-12108:Mailman before 2.1.31 allows Arbitrary Content Injection
CVE-2020-15011:Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py
CVE-2020-12137:Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts.
CVE-2021-42097:Mailman before 2.1.35 may allow remote Privilege Escalation.
CVE-2021-42096:A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force

Affected Version:
All versions from 2.1.29 Prior to ubuntu 3.1

A attacker could use this to perform a csrf attack to gain access to another account, brute force attack against the admin password, allow remote Privilege Escalation and Arbitrary Content Injection

  • CVSS V3 rated as High - 8 severity.
  • CVSS V2 rated as Critical - 8.5 severity.
  • Solution
    Refer to Ubuntu advisory: USN-5121-2 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    USN-5121-2 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5121-2