Boletines de Vulnerabilidades

DSA-3214 mailman - security update


Información sobre el sistema

   
Software afectado Debian

Descripción

A path traversal vulnerability was discovered in Mailman, the mailinglist manager. Installations using a transport script (such aspostfix-to-mailman.py) to interface with their MTA instead of staticaliases were vulnerable to a path traversal attack. To successfullyexploit this, an attacker needs write access on the local file system.

More info:

https://www.debian.org/security/2015/dsa-3214

Identificadores estándar

Propiedad Valor
CVE CVE-2015-2775 and DSA-3214.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-04-09

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT