==========================================================================
Ubuntu Security Notice USN-4406-1
June 29, 2020
mailman vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS
Summary:
Mailman could be made to inject arbitrary content in the login page if it
received a specially crafted input.
Software Description:
– mailman: Web-based mailing list manager (legacy branch)
Details:
It was discovered that Mailman incorrectly handled certain inputs.
An attacker could possibly use this issue to inject arbitrary content
in the login page.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS:
mailman 1:2.1.26-1ubuntu0.3
Ubuntu 16.04 LTS:
mailman 1:2.1.20-1ubuntu0.6
In general, a standard system update will make all the necessary changes.
References:
https://usn.ubuntu.com/4406-1
CVE-2020-15011
Package Information:
https://launchpad.net/ubuntu/+source/mailman/1:2.1.26-1ubuntu0.3
https://launchpad.net/ubuntu/+source/mailman/1:2.1.20-1ubuntu0.6
—–BEGIN PGP SIGNATURE—–
iQIzBAABCgAdFiEEf+ebRFcoyOoAQoOeRbznW4QLH2kFAl75/6UACgkQRbznW4QL
H2nZcQ/+LWxYoit0iWdgkYfp9bpm+b7cB6Uo9JfdRoyv9UlKW0xXWANDD9COLqYj
IkH/RDkDPkBpevMzJycm+9W7FwtJvkVnPh3hMnl5Ud61CSUAhrZg+InSolKJ3SwB
14aXfGJIoni9WizDWSQeO08Zd3jo7gS8Sb92c35DTIHBWivsNk5WMOiWUceYKCFR
OUVBzT+LUNI3yt9lqKXUYKDFBvCAyOz84V290cZKtv1PIcQJImn7ohsaJFttrG5i
xIn0yIjsBdOh4mePbngiX0ic3+XC13zlpHcKYzt8pDkEETZo7A3VE+GOv+Tn5CQa
dfItmqnpkUXKjx3V2ORS1cHxfrOul1kEWxZVcT5QLysK1VVrDSs46dRFoiIJRzlc
OQ5WwLaxMgWztbGNGfBlfmbSc0o3+KBeLY8DxZwEcTPIvCkwHIsHZF6O431WDrIz
WcOFclN0n0QM6tBflnnKy6Sg2SU4SAwSkVt4AK5yNpA5vQq3nKY3qNxPyg+Px6VX
willTxKqzWChjXWf5qmktWOEu7fMqe2vgA+/EuhHqnDiBgI0hoTvqw5sn3wymVET
T/zPtZxgDIWTxK/G1qq3TbEciL6Aa2K89ih+55F980NA+sVJLE8usKfbiaU4IT7R
7aEFFsCKPGUScwawq4gZKq4x+zE1JwXk5r7zry+SBvD0ftvke4I=
=qAg7
—–END PGP SIGNATURE—–
—