openSUSE-SU-2021:1436-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:1436-1
openSUSE-SU-2021:1436-1
Summary: Security update for mailman
Details: This update for mailman fixes the following issues: Update to 2.1.35 to fix 2 security issues: - A potential for for a list member to carry out an off-line brute force attack to obtain the list admin password has been reported by Andre Protas, Richard Cloke and Andy Nuttall of Apple. This is fixed. CVE-2021-42096 (boo#1191959, LP:#1947639) - A CSRF attack via the user options page could allow takeover of a users account. This is fixed. CVE-2021-42097 (boo#1191960, LP:#1947640) - make package build reproducible (boo#1047218)
References: https://lists.opensuse.org/archives/list/[email protected]/thread/DSDRER3UF4R57ILYOQY7J63PNAP2LA73/, https://bugzilla.suse.com/1047218, https://bugzilla.suse.com/1191959, https://bugzilla.suse.com/1191960, https://www.suse.com/security/cve/CVE-2021-42096, https://www.suse.com/security/cve/CVE-2021-42097
Affected packages
Package
Name: mailman
Purl: pkg:rpm/opensuse/mailman&distro=openSUSE%20Leap%2015.2
Affected ranges
Type: ECOSYSTEM
Events:
