Summary
The remote host is missing an update to mailman
announced via advisory DSA 2170-1.
Solution
For the oldstable distribution (lenny), these problems have been fixed in version 1:2.1.11-11+lenny2.
For the stable distribution (squeeze), this problem has been fixed in version 1:2.1.13-5.
For the testing (wheezy) and unstable distribution (sid), this problem has been fixed in version 1:2.1.14-1.
We recommend that you upgrade your mailman packages.
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%202170-1
Insight
Two cross site scripting vulnerabilities were been discovered in Mailman, a web-based mailing list manager. These allowed an attacker to retreive session cookies via inserting crafted JavaScript into confirmation messages (CVE-2011-0707) and in the list admin interface (CVE-2010-3089
oldstable only).
Severity
Classification
-
CVE CVE-2010-3089, CVE-2011-0707 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities