OESA-2021-1444
Dashboard / Vulnerabilities / OESA-2021-1444
OESA-2021-1444
Summary: mailman security update
Details: Mailman is free software for managing electronic mail discussion and e-newsletter lists. Mailman is integrated with the web, making it easy for users to manage their accounts and for list owners to administer their lists. Mailman supports built-in archiving, automatic bounce processing, content filtering, digest delivery, spam filters, and more. Security Fix(es): In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attack.(CVE-2021-43332) In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS.(CVE-2021-43331)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1444, https://nvd.nist.gov/vuln/detail/CVE-2021-43332, https://nvd.nist.gov/vuln/detail/CVE-2021-43331
Affected packages
Package
Name: mailman
Purl: pkg:rpm/openEuler/mailman&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
