Vulnerability Bulletins

DSA-3214 mailman - security update

   
Affected software Debian
 
A path traversal vulnerability was discovered in Mailman, the mailinglist manager. Installations using a transport script (such aspostfix-to-mailman.py) to interface with their MTA instead of staticaliases were vulnerable to a path traversal attack. To successfullyexploit this, an attacker needs write access on the local file system.

More info:

https://www.debian.org/security/2015/dsa-3214