Secunia Logo  
 
Ubuntu update for mailman
Secunia Advisory: SA18456
Release Date: 2006-01-16
Popularity: 5,639 views

Critical:
Moderately critical
Impact: DoS
Where: From remote
Solution Status: Vendor Patch

OS:Ubuntu Linux 4.10
Ubuntu Linux 5.04
Ubuntu Linux 5.10

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2005-3573
CVE-2005-4153


Description:
Ubuntu has issued an update for mailman. This fixes two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).

For more information:
SA17511
SA18449

Solution:
Apply updated packages.

-- Ubuntu 4.10 --

Source archives:

http://security.ubuntu.com/ubuntu/poo...lman/mailman_2.1.5-1ubuntu2.5.diff.gz
Size/MD5: 128899 1686924bbacf9fefa556fd7f1e8f74dc
http://security.ubuntu.com/ubuntu/poo.../mailman/mailman_2.1.5-1ubuntu2.5.dsc
Size/MD5: 658 65e41dc9eb2456d8189aea0eb4df64ae
http://security.ubuntu.com/ubuntu/pool/main/m/mailman/mailman_2.1.5.orig.tar.gz
Size/MD5: 5745912 f5f56f04747cd4aff67427e7a45631af

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/poo...an/mailman_2.1.5-1ubuntu2.5_amd64.deb
Size/MD5: 6602720 b559d0c6c0c8d97dc6ea342a4911d154

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/poo...man/mailman_2.1.5-1ubuntu2.5_i386.deb
Size/MD5: 6602194 ad5e65cead5a9d90ddbffc736337fb94

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/poo.../mailman_2.1.5-1ubuntu2.5_powerpc.deb
Size/MD5: 6611016 89feb8e459fa9f34ff91c8bbf75f3a80

-- Ubuntu 5.04 --

Source archives:

http://security.ubuntu.com/ubuntu/poo...lman/mailman_2.1.5-7ubuntu0.1.diff.gz
Size/MD5: 118355 78b91e2f11e438ef259c3e67e6fd1d47
http://security.ubuntu.com/ubuntu/poo.../mailman/mailman_2.1.5-7ubuntu0.1.dsc
Size/MD5: 669 99b42b16f8c4ba4e8acacc73920d1639
http://security.ubuntu.com/ubuntu/pool/main/m/mailman/mailman_2.1.5.orig.tar.gz
Size/MD5: 5745912 f5f56f04747cd4aff67427e7a45631af

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/poo...an/mailman_2.1.5-7ubuntu0.1_amd64.deb
Size/MD5: 6609778 28b3e1f005cbcc097fb084ba3b0c313b

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/poo...man/mailman_2.1.5-7ubuntu0.1_i386.deb
Size/MD5: 6609308 f80df6c6bc8f6a028d065c8892849569

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/poo.../mailman_2.1.5-7ubuntu0.1_powerpc.deb
Size/MD5: 6616534 f33e0b4a6d2afea8aa96f3e86fdfe579

-- Ubuntu 5.10 --

Source archives:

http://security.ubuntu.com/ubuntu/poo...lman/mailman_2.1.5-8ubuntu2.1.diff.gz
Size/MD5: 194039 fd67dfe7d97bd94e9ad0e0575599639d
http://security.ubuntu.com/ubuntu/poo.../mailman/mailman_2.1.5-8ubuntu2.1.dsc
Size/MD5: 626 63366d888d62e4769c331c7303716c2e
http://security.ubuntu.com/ubuntu/pool/main/m/mailman/mailman_2.1.5.orig.tar.gz
Size/MD5: 5745912 f5f56f04747cd4aff67427e7a45631af

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/poo...an/mailman_2.1.5-8ubuntu2.1_amd64.deb
Size/MD5: 6610440 165e35634f6767fbab615e9407eec4c8

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/poo...man/mailman_2.1.5-8ubuntu2.1_i386.deb
Size/MD5: 6609374 03e1822d1085b4ff27d3ecb2912048bf

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/poo.../mailman_2.1.5-8ubuntu2.1_powerpc.deb
Size/MD5: 6617106 522653cd7ecdce70366a2d80b5b97460

Original Advisory:
http://www.ubuntu.com/usn/usn-242-1

Other References:
SA17511:
http://secunia.com/advisories/17511/

SA18449:
http://secunia.com/advisories/18449/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Internet Explorer Data Binding Memory Corruption Vulnerability // 35 views
2. phpBB reveals user IPs // 31 views
3. Sun Java JDK / JRE Multiple Vulnerabilities // 30 views
4. Cisco Global Site Selector DNS Request Denial of Service // 29 views
5. Drupal Project Module File Upload and Cross-Site Scripting // 28 views
6. phpBB Avatar Functions Information Disclosure and Deletion // 28 views
7. EVA-Web Multiple Cross-Site Scripting Vulnerabilities // 28 views
8. NTP OpenSSL "EVP_VerifyFinal()" Spoofing Vulnerability // 25 views
9. SmbFTPD Long Command Processing Vulnerability // 25 views
10. tnftpd Long Command Processing Vulnerability // 25 views