PT-2020-3649 · Gnu+6 · Gnu Mailman+6

Hanno Böck

·

Published

2020-04-24

·

Updated

2022-11-16

·

CVE-2020-12137

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GNU Mailman versions 2.x through 2.1.29 GNU Mailman version 2.1.30 is not affected, but all versions prior to 2.1.30 are vulnerable.
Description The issue is related to the handling of MIME parts in GNU Mailman, which may contribute to cross-site scripting (XSS) attacks against visitors of list archives. This occurs because an HTTP reply from an archive web server may lack a MIME type, leading a web browser to perform MIME sniffing and potentially execute JavaScript code. The vulnerability is also related to the lack of protection for the web page structure, which could allow a remote attacker to impact data integrity.
Recommendations For GNU Mailman versions 2.x through 2.1.29, update to version 2.1.30 or later to resolve the issue. As a temporary workaround, consider restricting access to list archives to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2129
ALT-PU-2021-2036
ALT-PU-2021-2340
BDU:2020-03997
CESA-2020_4667
CVE-2020-12137
DLA-2200-1
DSA-4664-1
MGASA-2020-0276
OESA-2021-1405
OPENSUSE-SU-2020:1707-1
OPENSUSE-SU-2020:1752-1
OPENSUSE-SU-2020_1707-1
RHSA-2020:4667
RHSA-2020_4667
SUSE-SU-2020:1301-1
SUSE-SU-2020:14356-1
SUSE-SU-2020_14356-1
USN-4348-1
USN-5121-2

Affected Products

Alt Linux
Centos
Gnu Mailman
Linuxmint
Red Hat
Suse
Ubuntu