Search 211766 CVE descriptions
and 97459 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2007:0779

The remote host is missing updates announced in
advisory RHSA-2007:0779.

Mailman is a program used to help manage email discussion lists.

A flaw was found in Mailman. A remote attacker could spoof messages in
the error log, and possibly trick the administrator into visiting malicious
URLs via a carriage return/line feed sequence in the URI. (CVE-2006-4624)

As well, these updated packages fix the following bugs:

* canceling a subscription on the confirm subscription request page
caused mailman to crash.

* editing the sender filter caused all spam filter rules to be deleted.

* the migrate-fhs script was not included.

* the mailman init script returned a zero (success) exit code even when
an incorrect command was given. For example, the mailman foo command
returned a zero exit code. In these updated packages the mailmain init
script returns the correct exit codes.

Users of Mailman are advised to upgrade to these updated packages, which
resolve these issues.

Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

Risk factor : Medium

CVSS Score:

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2006-4624
BugTraq ID: 19831
BugTraq ID: 20021
Bugtraq: 20060913 Mailman 2.1.8 Multiple Security Issues (Google Search)
Debian Security Information: DSA-1188 (Google Search)
SuSE Security Announcement: SUSE-SR:2006:025 (Google Search)
XForce ISS Database: mailman-admin-spoofing(28734)
CopyrightCopyright (c) 2007 E-Soft Inc.

This is only one of 97459 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

© 1998-2021 E-Soft Inc. All rights reserved.