Secunia - Stay Secure
Home Corporate Website Jobs  Mailing Lists RSS Blog  Online Shop Advertise
Software Inspectors
  Scan Online
  Personal (PSI)
  Network (NSI 2.0)

Solutions For
  Security Professionals
  Security Vendors

Free Solutions For
  Open Communities
  Journalists & Media

Secunia Advisories
  Search
  Historic Advisories
  Listed By Product
  Listed By Vendor
  Statistics / Graphs
  Secunia Research
  Report Vulnerability
  About Advisories

Virus Information
  Chronological List
  Last 10 Virus Alerts
  About Virus Information

Secunia Customers
  Customer Area


Debian update for mailman Advisory Available in Danish 

Secunia Advisory: SA22227  
Release Date: 2006-10-04

Critical:
Less critical
Impact: Cross Site Scripting
Spoofing
Where: From remote
Solution Status: Vendor Patch

OS:Debian GNU/Linux 3.1
Debian GNU/Linux unstable alias sid


CVE reference:CVE-2006-3636 (Secunia mirror)
CVE-2006-4624 (Secunia mirror)

Want to know the next time vulnerabilities are fixed in this product?
- Companies can be alerted via email and SMS!


Description:
Debian has issued an update for mailman. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and phishing attacks.

For more information:
SA21732

Solution:
Apply updated packages.

-- Debian GNU/Linux 3.1 alias sarge --

Source archives:

http://security.debian.org/pool/updates/main/m/mailman/mailman_2.1.5-8sarge5.dsc
Size/MD5 checksum: 816 3f2cd37005f340202f0c7660d8c91196
http://security.debian.org/pool/updat...mailman/mailman_2.1.5-8sarge5.diff.gz
Size/MD5 checksum: 122128 292c5264aeffbd2079b5a3257b165de0
http://security.debian.org/pool/updates/main/m/mailman/mailman_2.1.5.orig.tar.gz
Size/MD5 checksum: 5745912 f5f56f04747cd4aff67427e7a45631af

Alpha architecture:

http://security.debian.org/pool/updat...ilman/mailman_2.1.5-8sarge5_alpha.deb
Size/MD5 checksum: 6612236 6e98b9f63c0eb5168902fb863167a197

AMD64 architecture:

http://security.debian.org/pool/updat...ilman/mailman_2.1.5-8sarge5_amd64.deb
Size/MD5 checksum: 6611036 3ca3419b399ec2a8a9a398e81d744d07

ARM architecture:

http://security.debian.org/pool/updat...mailman/mailman_2.1.5-8sarge5_arm.deb
Size/MD5 checksum: 6610764 e2d64ba3fe9dc2883d48cbcfcb016bbe

HP Precision architecture:

http://security.debian.org/pool/updat...ailman/mailman_2.1.5-8sarge5_hppa.deb
Size/MD5 checksum: 6617802 14f8c5db2d8e38c470e3375a7e2102bb

Intel IA-32 architecture:

http://security.debian.org/pool/updat...ailman/mailman_2.1.5-8sarge5_i386.deb
Size/MD5 checksum: 6606630 112c41dadf9efdf4823ad5c32180fe0e

Intel IA-64 architecture:

http://security.debian.org/pool/updat...ailman/mailman_2.1.5-8sarge5_ia64.deb
Size/MD5 checksum: 6612188 d6a6b7fd9613f4d7a7ac6b59ffff40f9

Motorola 680x0 architecture:

http://security.debian.org/pool/updat...ailman/mailman_2.1.5-8sarge5_m68k.deb
Size/MD5 checksum: 6617856 ebe2b791034f4d08461b2d2c6d60f37d

Big endian MIPS architecture:

http://security.debian.org/pool/updat...ailman/mailman_2.1.5-8sarge5_mips.deb
Size/MD5 checksum: 6661270 2412e64f5406bc1e84d3e64fc9e5a9fc

Little endian MIPS architecture:

http://security.debian.org/pool/updat...lman/mailman_2.1.5-8sarge5_mipsel.deb
Size/MD5 checksum: 6652256 816264d9b311c02fc99d68dd62604cef

PowerPC architecture:

http://security.debian.org/pool/updat...man/mailman_2.1.5-8sarge5_powerpc.deb
Size/MD5 checksum: 6618128 6c5974478f4b877ddd47c115d66075f1

IBM S/390 architecture:

http://security.debian.org/pool/updat...ailman/mailman_2.1.5-8sarge5_s390.deb
Size/MD5 checksum: 6617184 6977902eb91d3eab34141d0de34f0323

Sun Sparc architecture:

http://security.debian.org/pool/updat...ilman/mailman_2.1.5-8sarge5_sparc.deb
Size/MD5 checksum: 6616594 3847454bf1b64d728f7e6bcaf57dea89

-- Debian GNU/Linux unstable alias sid --

Fixed in version 2.1.8-3.

Original Advisory:
http://www.us.debian.org/security/2006/dsa-1188

Other References:
SA21732:
http://secunia.com/advisories/21732/



Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.

1216 Related Secunia Security Advisories, displaying 10

1. Debian update for slash
2. Debian update for wordnet
3. Debian update for tiff
4. Debian update for libxml2
5. Debian update for postfix
6. Debian update for pdns
7. Debian update for httracker
8. Debian update for opensc
9. Debian update for cupsys
10. Debian update for libxslt

Show all related advisories


Send Feedback to Secunia

If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.








Secunia PSI
Scan | Patch | Track
Free Download

Secunia Poll

Do you think it's important to read Setup/User Guides for applications for use within your network?


See Results   


Most Popular Advisories

1.
HP OpenView Select Identity Connectors Information Disclosure
2.
Gentoo update for yelp
3.
Drupal Content Construction Kit Script Insertion Vulnerabilities
4.
Gentoo update for dnsmasq
5.
Gentoo update for mysql
6.
Gentoo update for realplayer
7.
rPath update for libtiff
8.
CS-Cart "cs_cookies" SQL Injection Vulnerability
9.
Cisco ASA and PIX Security Appliances Multiple Vulnerabilities
10.
SUSE update for IBMJava5-JRE and java-1_5_0-ibm





Vulnerability Management - Terms & Conditions - Copyright 2002-2008 Secunia - Compliance - Contact Secunia