GNU Mailman CVE-2018-5950 Cross Site Scripting Vulnerability



GNU Mailman is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to GNU Mailman 2.1.26 are vulnerable.

Information

Bugtraq ID: 104594
Class: Input Validation Error
CVE: CVE-2018-5950

Remote: Yes
Local: No
Published: Jul 03 2018 12:00AM
Updated: Jul 03 2018 12:00AM
Credit: Salvatore Bonaccorso
Vulnerable: Redhat Enterprise Linux 7
Redhat Enterprise Linux 6
+ Trustix Secure Enterprise Linux 2.0
+ Trustix Secure Linux 2.2
+ Trustix Secure Linux 2.1
+ Trustix Secure Linux 2.0
Redhat Enterprise Linux 5
GNU Mailman 2.1.25
GNU Mailman 2.1.24
GNU Mailman 2.1.22
GNU Mailman 2.1.20
GNU Mailman 2.1.19
GNU Mailman 2.1.18
GNU Mailman 2.1.17
GNU Mailman 2.1.16
GNU Mailman 2.1.15
GNU Mailman 2.1.12
GNU Mailman 2.1.11
GNU Mailman 2.1.10 b1
GNU Mailman 2.1.9 rc1
GNU Mailman 2.1.9
GNU Mailman 2.1.8 rc1
GNU Mailman 2.1.7
GNU Mailman 2.1.6
GNU Mailman 2.1.5
+ Debian Linux 3.1 sparc
+ Debian Linux 3.1 s/390
+ Debian Linux 3.1 ppc
+ Debian Linux 3.1 mipsel
+ Debian Linux 3.1 mips
+ Debian Linux 3.1 m68k
+ Debian Linux 3.1 ia-64
+ Debian Linux 3.1 ia-32
+ Debian Linux 3.1 hppa
+ Debian Linux 3.1 arm
+ Debian Linux 3.1 amd64
+ Debian Linux 3.1 alpha
+ Debian Linux 3.1
+ Mandriva Linux Mandrake 10.1 x86_64
+ Mandriva Linux Mandrake 10.1
+ Redhat Enterprise Linux Desktop version 4
+ Redhat Enterprise Linux AS 4
+ Redhat Enterprise Linux AS 3
+ Redhat Enterprise Linux ES 4
+ Redhat Enterprise Linux ES 3
+ Redhat Enterprise Linux WS 4
+ Redhat Enterprise Linux WS 3
GNU Mailman 2.1.4
+ MandrakeSoft Corporate Server 3.0
+ Mandriva Linux Mandrake 10.0 AMD64
+ Mandriva Linux Mandrake 10.0
GNU Mailman 2.1.3
GNU Mailman 2.1.2
+ Mandriva Linux Mandrake 9.2 amd64
+ Mandriva Linux Mandrake 9.2
GNU Mailman 2.1.1
+ Redhat Linux 9.0 i386
+ Redhat Linux 7.3 i686
+ Redhat Linux 7.3 i386
+ Redhat Linux 7.3
GNU Mailman 2.1
GNU Mailman 2.0.14
+ MandrakeSoft Corporate Server 2.1 x86_64
+ MandrakeSoft Corporate Server 2.1
GNU Mailman 2.0.13
+ Redhat Enterprise Linux AS 2.1 IA64
+ Redhat Enterprise Linux AS 2.1
+ Redhat Enterprise Linux ES 2.1 IA64
+ Redhat Enterprise Linux ES 2.1
+ Redhat Enterprise Linux WS 2.1 IA64
+ Redhat Enterprise Linux WS 2.1
GNU Mailman 2.0.12
GNU Mailman 2.0.11
+ Debian Linux 3.0
GNU Mailman 2.0.10
GNU Mailman 2.0.9
GNU Mailman 2.0.8
+ Redhat Linux 7.3 i386
+ Redhat Linux 7.2 ia64
+ Redhat Linux 7.2 i386
- Redhat PowerTools 7.1
- Redhat PowerTools 7.0
GNU Mailman 2.0.7
GNU Mailman 2.0.6
GNU Mailman 2.0.5
- Debian Linux 2.2 sparc
- Debian Linux 2.2 powerpc
- Debian Linux 2.2 arm
- Debian Linux 2.2 alpha
- Debian Linux 2.2 68k
- Debian Linux 2.2
- FreeBSD FreeBSD 4.3
- HP HP-UX 11.11
- HP HP-UX 11.0
- HP HP-UX 10.20
- Mandriva Linux Mandrake 8.0
- Mandriva Linux Mandrake 7.2
- Mandriva Linux Mandrake 7.1
- NetBSD NetBSD 1.5.2
- NetBSD NetBSD 1.5.1
- OpenBSD OpenBSD 2.9
- OpenBSD OpenBSD 2.8
- OpenBSD OpenBSD 2.7
- Redhat Linux 7.1
- Redhat Linux 7.0
- Slackware Linux 8.0
- Slackware Linux 7.1
- Slackware Linux 7.0
- Sun Solaris 8_sparc
- Sun Solaris 7.0
- Sun Solaris 2.6
- SuSE Linux 7.2
- SuSE Linux 7.1
- SuSE Linux 7.0
GNU Mailman 2.0.4
GNU Mailman 2.0.3
GNU Mailman 2.0.2
GNU Mailman 2.0.1
GNU Mailman 2.1.23
GNU Mailman 2.1.14rc1
+ Debian Linux 3.1 sparc
+ Debian Linux 3.1 s/390
+ Debian Linux 3.1 ppc
+ Debian Linux 3.1 mipsel
+ Debian Linux 3.1 mips
+ Debian Linux 3.1 m68k
+ Debian Linux 3.1 ia-64
+ Debian Linux 3.1 ia-32
+ Debian Linux 3.1 hppa
+ Debian Linux 3.1 arm
+ Debian Linux 3.1 amd64
+ Debian Linux 3.1 alpha
+ Debian Linux 3.1
+ Mandriva Linux Mandrake 10.1 x86_64
+ Mandriva Linux Mandrake 10.1
+ Redhat Enterprise Linux Desktop version 4
+ Redhat Enterprise Linux AS 4
+ Redhat Enterprise Linux AS 3
+ Redhat Enterprise Linux ES 4
+ Redhat Enterprise Linux ES 3
+ Redhat Enterprise Linux WS 4
+ Redhat Enterprise Linux WS 3
GNU Mailman 2.1.14 Rc1
GNU Mailman 2.1.14
+ Debian Linux 3.1 sparc
+ Debian Linux 3.1 s/390
+ Debian Linux 3.1 ppc
+ Debian Linux 3.1 mipsel
+ Debian Linux 3.1 mips
+ Debian Linux 3.1 m68k
+ Debian Linux 3.1 ia-64
+ Debian Linux 3.1 ia-32
+ Debian Linux 3.1 hppa
+ Debian Linux 3.1 arm
+ Debian Linux 3.1 amd64
+ Debian Linux 3.1 alpha
+ Debian Linux 3.1
+ Mandriva Linux Mandrake 10.1 x86_64
+ Mandriva Linux Mandrake 10.1
+ Redhat Enterprise Linux Desktop version 4
+ Redhat Enterprise Linux AS 4
+ Redhat Enterprise Linux AS 3
+ Redhat Enterprise Linux ES 4
+ Redhat Enterprise Linux ES 3
+ Redhat Enterprise Linux WS 4
+ Redhat Enterprise Linux WS 3
GNU Mailman 2.1.13 Rc1
GNU Mailman 2.1.13
+ Debian Linux 3.1 sparc
+ Debian Linux 3.1 s/390
+ Debian Linux 3.1 ppc
+ Debian Linux 3.1 mipsel
+ Debian Linux 3.1 mips
+ Debian Linux 3.1 m68k
+ Debian Linux 3.1 ia-64
+ Debian Linux 3.1 ia-32
+ Debian Linux 3.1 hppa
+ Debian Linux 3.1 arm
+ Debian Linux 3.1 amd64
+ Debian Linux 3.1 alpha
+ Debian Linux 3.1
+ Mandriva Linux Mandrake 10.1 x86_64
+ Mandriva Linux Mandrake 10.1
+ Redhat Enterprise Linux Desktop version 4
+ Redhat Enterprise Linux AS 4
+ Redhat Enterprise Linux AS 3
+ Redhat Enterprise Linux ES 4
+ Redhat Enterprise Linux ES 3
+ Redhat Enterprise Linux WS 4
+ Redhat Enterprise Linux WS 3
GNU Mailman 2.1.11 Rc2
GNU Mailman 2.1.11 Rc1
GNU Mailman 2.1.10b1
GNU Mailman 2.1.10
GNU Mailman 2.1 Stable
GNU Mailman 2.1 Beta
GNU Mailman 2.1 Alpha


Not Vulnerable: GNU Mailman 2.1.26


Exploit


Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.


Related Posts