CVE-2011-0707
Publication date 18 February 2011
Last updated 24 July 2024
Ubuntu priority
Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) username field in a confirmation message.
Status
Package | Ubuntu Release | Status |
---|---|---|
mailman | 10.10 maverick |
Fixed 1:2.1.13-4ubuntu0.2
|
10.04 LTS lucid |
Fixed 1:2.1.13-1ubuntu0.2
|
|
9.10 karmic |
Fixed 1:2.1.12-2ubuntu0.2
|
|
8.04 LTS hardy |
Fixed 1:2.1.9-9ubuntu1.4
|
|
6.06 LTS dapper |
Fixed 2.1.5-9ubuntu4.4
|
Patch details
Package | Patch details |
---|---|
mailman |
References
Related Ubuntu Security Notices (USN)
- USN-1069-1
- Mailman vulnerabilities
- 22 February 2011