Mailing the story:

Debian alert: New mailman packages fix cross-site scripting problem

  • Mailing list (Posted by on CST)
  • Story Type: Security; Groups: Debian
A cross-site scripting vulnerability was discovered in mailman, a software to manage electronic mailing lists. When a properly crafted URL is accessed with Internet Explorer (other browsers don't seem to be affected), the resulting webpage is rendered similar to the real one, but the javascript component is executed as well, which could be used by an attacker to get access to sensitive information. The new version for Debian 2.2 also includes backports of security related patches from mailman 2.0.11.
What is your name?

What is your E-Mail address?

What is the email address of the recipient?

Add a special note from yourself?