UBUNTU-CVE-2020-12137
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-12137
UBUNTU-CVE-2020-12137
Summary:
Details: GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code.
References: https://ubuntu.com/security/CVE-2020-12137, https://www.openwall.com/lists/oss-security/2020/02/24/2, http://bazaar.launchpad.net/~mailman-coders/mailman/2.1/revision/1801, http://bazaar.launchpad.net/~mailman-coders/mailman/2.1/view/head:/NEWS, http://www.openwall.com/lists/oss-security/2020/04/24/3, https://www.openwall.com/lists/oss-security/2020/02/24/3, https://ubuntu.com/security/notices/USN-4348-1, https://ubuntu.com/security/notices/USN-5121-2, https://www.cve.org/CVERecord?id=CVE-2020-12137
Affected packages
Package
Name: mailman
Purl: pkg:deb/ubuntu/mailman@1:2.1.20-1ubuntu0.4?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
