Vulnerability Bulletins

DSA-4246 mailman - security update

   
Affected software Debian
 
Toshitsugu Yoneyama of Mitsui Bussan Secure Directions, Inc. discoveredthat mailman, a web-based mailing list manager, is prone to a cross-sitescripting flaw allowing a malicious listowner to inject scripts into thelistinfo page, due to not validated input in the host_name field.

More info:

https://www.debian.org/security/2018/dsa-4246