mailman: The GNU Mailing List Manager ---------------------------------------------------------------------- File: mailman-2.1.7-15.5.i586.rpm Patchrpm: mailman-2.1.7-15.5.i586.patch.rpm Version: 2.1.7-15.5 Size: 5398 kB Patchsize: 514 kB Date: Sat 14 Oct 2006 1:1:56 CEST Source: mailman-2.1.7-15.5.src.rpm Security: Yes ---------------------------------------------------------------------- Description: This update of mailman fixes the following security issues: - A malicious user could visit a specially crafted URI and inject an apparent log message into Mailman's error log which might induce an unsuspecting administrator to visit a phishing site. This has been blocked. Thanks to Moritz Naumann for its discovery. - Fixed denial of service attack which can be caused by some standards-breaking RFC 2231 formatted headers. CVE-2006-2941. - Several cross-site scripting issues have been fixed. Thanks to Moritz Naumann for their discovery. CVE-2006-3636 - Fixed an unexploitable format string vulnerability. Discovery and fix by Karl Chen. Analysis of non-exploitability by Martin 'Joey' Schulze. Also thanks go to Lionel Elie Mamane. CVE-2006-2191.