GNU Mailman is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to GNU Mailman 2.1.26 are vulnerable.
Information
Bugtraq ID: | 104594 | Class: | Input Validation Error | CVE: | CVE-2018-5950
| Remote: | Yes | Local: | No | Published: | Jul 03 2018 12:00AM | Updated: | Jul 03 2018 12:00AM | Credit: | Salvatore Bonaccorso | Vulnerable: | Redhat Enterprise Linux 7 Redhat Enterprise Linux 6 + Trustix Secure Enterprise Linux 2.0 + Trustix Secure Linux 2.2 + Trustix Secure Linux 2.1 + Trustix Secure Linux 2.0 Redhat Enterprise Linux 5 GNU Mailman 2.1.25 GNU Mailman 2.1.24 GNU Mailman 2.1.22 GNU Mailman 2.1.20 GNU Mailman 2.1.19 GNU Mailman 2.1.18 GNU Mailman 2.1.17 GNU Mailman 2.1.16 GNU Mailman 2.1.15 GNU Mailman 2.1.12 GNU Mailman 2.1.11 GNU Mailman 2.1.10 b1 GNU Mailman 2.1.9 rc1 GNU Mailman 2.1.9 GNU Mailman 2.1.8 rc1 GNU Mailman 2.1.7 GNU Mailman 2.1.6 GNU Mailman 2.1.5 + Debian Linux 3.1 sparc + Debian Linux 3.1 s/390 + Debian Linux 3.1 ppc + Debian Linux 3.1 mipsel + Debian Linux 3.1 mips + Debian Linux 3.1 m68k + Debian Linux 3.1 ia-64 + Debian Linux 3.1 ia-32 + Debian Linux 3.1 hppa + Debian Linux 3.1 arm + Debian Linux 3.1 amd64 + Debian Linux 3.1 alpha + Debian Linux 3.1 + Mandriva Linux Mandrake 10.1 x86_64 + Mandriva Linux Mandrake 10.1 + Redhat Enterprise Linux Desktop version 4 + Redhat Enterprise Linux AS 4 + Redhat Enterprise Linux AS 3 + Redhat Enterprise Linux ES 4 + Redhat Enterprise Linux ES 3 + Redhat Enterprise Linux WS 4 + Redhat Enterprise Linux WS 3 GNU Mailman 2.1.4 + MandrakeSoft Corporate Server 3.0 + Mandriva Linux Mandrake 10.0 AMD64 + Mandriva Linux Mandrake 10.0 GNU Mailman 2.1.3 GNU Mailman 2.1.2 + Mandriva Linux Mandrake 9.2 amd64 + Mandriva Linux Mandrake 9.2 GNU Mailman 2.1.1 + Redhat Linux 9.0 i386 + Redhat Linux 7.3 i686 + Redhat Linux 7.3 i386 + Redhat Linux 7.3 GNU Mailman 2.1 GNU Mailman 2.0.14 + MandrakeSoft Corporate Server 2.1 x86_64 + MandrakeSoft Corporate Server 2.1 GNU Mailman 2.0.13 + Redhat Enterprise Linux AS 2.1 IA64 + Redhat Enterprise Linux AS 2.1 + Redhat Enterprise Linux ES 2.1 IA64 + Redhat Enterprise Linux ES 2.1 + Redhat Enterprise Linux WS 2.1 IA64 + Redhat Enterprise Linux WS 2.1 GNU Mailman 2.0.12 GNU Mailman 2.0.11 + Debian Linux 3.0 GNU Mailman 2.0.10 GNU Mailman 2.0.9 GNU Mailman 2.0.8 + Redhat Linux 7.3 i386 + Redhat Linux 7.2 ia64 + Redhat Linux 7.2 i386 - Redhat PowerTools 7.1 - Redhat PowerTools 7.0 GNU Mailman 2.0.7 GNU Mailman 2.0.6 GNU Mailman 2.0.5 - Debian Linux 2.2 sparc - Debian Linux 2.2 powerpc - Debian Linux 2.2 arm - Debian Linux 2.2 alpha - Debian Linux 2.2 68k - Debian Linux 2.2 - FreeBSD FreeBSD 4.3 - HP HP-UX 11.11 - HP HP-UX 11.0 - HP HP-UX 10.20 - Mandriva Linux Mandrake 8.0 - Mandriva Linux Mandrake 7.2 - Mandriva Linux Mandrake 7.1 - NetBSD NetBSD 1.5.2 - NetBSD NetBSD 1.5.1 - OpenBSD OpenBSD 2.9 - OpenBSD OpenBSD 2.8 - OpenBSD OpenBSD 2.7 - Redhat Linux 7.1 - Redhat Linux 7.0 - Slackware Linux 8.0 - Slackware Linux 7.1 - Slackware Linux 7.0 - Sun Solaris 8_sparc - Sun Solaris 7.0 - Sun Solaris 2.6 - SuSE Linux 7.2 - SuSE Linux 7.1 - SuSE Linux 7.0 GNU Mailman 2.0.4 GNU Mailman 2.0.3 GNU Mailman 2.0.2 GNU Mailman 2.0.1 GNU Mailman 2.1.23 GNU Mailman 2.1.14rc1 + Debian Linux 3.1 sparc + Debian Linux 3.1 s/390 + Debian Linux 3.1 ppc + Debian Linux 3.1 mipsel + Debian Linux 3.1 mips + Debian Linux 3.1 m68k + Debian Linux 3.1 ia-64 + Debian Linux 3.1 ia-32 + Debian Linux 3.1 hppa + Debian Linux 3.1 arm + Debian Linux 3.1 amd64 + Debian Linux 3.1 alpha + Debian Linux 3.1 + Mandriva Linux Mandrake 10.1 x86_64 + Mandriva Linux Mandrake 10.1 + Redhat Enterprise Linux Desktop version 4 + Redhat Enterprise Linux AS 4 + Redhat Enterprise Linux AS 3 + Redhat Enterprise Linux ES 4 + Redhat Enterprise Linux ES 3 + Redhat Enterprise Linux WS 4 + Redhat Enterprise Linux WS 3 GNU Mailman 2.1.14 Rc1 GNU Mailman 2.1.14 + Debian Linux 3.1 sparc + Debian Linux 3.1 s/390 + Debian Linux 3.1 ppc + Debian Linux 3.1 mipsel + Debian Linux 3.1 mips + Debian Linux 3.1 m68k + Debian Linux 3.1 ia-64 + Debian Linux 3.1 ia-32 + Debian Linux 3.1 hppa + Debian Linux 3.1 arm + Debian Linux 3.1 amd64 + Debian Linux 3.1 alpha + Debian Linux 3.1 + Mandriva Linux Mandrake 10.1 x86_64 + Mandriva Linux Mandrake 10.1 + Redhat Enterprise Linux Desktop version 4 + Redhat Enterprise Linux AS 4 + Redhat Enterprise Linux AS 3 + Redhat Enterprise Linux ES 4 + Redhat Enterprise Linux ES 3 + Redhat Enterprise Linux WS 4 + Redhat Enterprise Linux WS 3 GNU Mailman 2.1.13 Rc1 GNU Mailman 2.1.13 + Debian Linux 3.1 sparc + Debian Linux 3.1 s/390 + Debian Linux 3.1 ppc + Debian Linux 3.1 mipsel + Debian Linux 3.1 mips + Debian Linux 3.1 m68k + Debian Linux 3.1 ia-64 + Debian Linux 3.1 ia-32 + Debian Linux 3.1 hppa + Debian Linux 3.1 arm + Debian Linux 3.1 amd64 + Debian Linux 3.1 alpha + Debian Linux 3.1 + Mandriva Linux Mandrake 10.1 x86_64 + Mandriva Linux Mandrake 10.1 + Redhat Enterprise Linux Desktop version 4 + Redhat Enterprise Linux AS 4 + Redhat Enterprise Linux AS 3 + Redhat Enterprise Linux ES 4 + Redhat Enterprise Linux ES 3 + Redhat Enterprise Linux WS 4 + Redhat Enterprise Linux WS 3 GNU Mailman 2.1.11 Rc2 GNU Mailman 2.1.11 Rc1 GNU Mailman 2.1.10b1 GNU Mailman 2.1.10 GNU Mailman 2.1 Stable GNU Mailman 2.1 Beta GNU Mailman 2.1 Alpha
| | Not Vulnerable: | GNU Mailman 2.1.26
| Exploit
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.