PT-2005-1285 · Gnu+1 · Mailman+1

Published

2005-02-09

·

Updated

2017-10-11

·

CVE-2005-0202

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mailman versions 2.1.5 and earlier
Description A directory traversal issue exists in the true path function in private.py, allowing remote attackers to read arbitrary files by utilizing ".../....///" sequences. These sequences are not properly removed by regular expressions intended to cleanse "../" and "./" sequences.
Recommendations For Mailman versions 2.1.5 and earlier, consider restricting access to sensitive files and directories until a patch is available. As a temporary workaround, review and modify the true path function in private.py to properly handle and cleanse directory traversal sequences.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0202
DSA-674-1
RHSA-2005:136
RHSA-2005:137
RHSA-2005_136
RHSA-2005_137

Affected Products

Mailman
Red Hat