USN-3118-1: Mailman vulnerabilities
USN-3118-1: Mailman vulnerabilities Ubuntu Security Notice USN-3118-1 1st November, 2016 mailman vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Several security issues were fixed in Mailman. Software description mailman – Powerful, web-based mailing list manager Details It was discovered that the Mailman administrative web interface did notprotect against cross-site request forgery (CSRF) attacks. If anauthenticated user were tricked into visiting a malicious website whilelogged into Mailman, a remote attacker could perform administrativeactions. This issue only affected Ubuntu 12.04 LTS. (CVE-2016-7123) Nishant Agarwala discovered that the Mailman user options page did notprotect against cross-site request forgery (CSRF) attacks. If anauthenticated user were tricked into visiting a malicious website whilelogged into Mailman, a remote attacker could modify user options.(CVE-2016-6893) Update instructions The problem can be corrected [ more… ]