int(5727)

Vulnerability Bulletins


Cross-site scripting en GNU Mailman

Vulnerability classification

Property Value
Confidence level Oficial
Impact Obtener acceso
Dificulty Experto
Required attacker level Acceso remoto con cuenta

System information

Property Value
Affected manufacturer GNU/Linux
Affected software GNU Mailman

Description

CVE-2010-3089: Se ha descubierto una vulnerabilidad de cross-site scripting (XSS) en GNU Mailman versiones anteriores a 2.1.14rc1.
Un atacante remoto podría inyectar código HTML mediante vectores que incluyen un campo de información.

Solution



Actualización de software

Red Hat (RHSA-2011:0307-1)
RHEL Desktop Workstation (v. 5 client)
Red Hat Enterprise Linux (v. 5 server)
Red Hat Enterprise Linux AS version 4
Red Hat Enterprise Linux Desktop version 4
Red Hat Enterprise Linux ES version 4
Red Hat Enterprise Linux WS version 4
https://rhn.redhat.com/

Standar resources

Property Value
CVE CVE-2010-3089
BID

Other resources

Red Hat Security Advisory (RHSA-2011:0307-01)
https://rhn.redhat.com/errata/RHSA-2011-0307.html

Version history

Version Comments Date
1.0 Aviso emitido 2011-03-10