Code Injection in Gnu - CVE-2020-15011
Published: June 30, 2020
Vulnerability details
The vulnerability allows a remote attacker to inject arbitrary content.
The vulnerability exists due to improper input validation within the Cgi/private.py private archive login page. A remote attacker can send a specially crafted request and inject arbitrary content.
Successful exploitation of the vulnerability requires that the roster visibility (private_roster) setting is 'Anyone'.
Affected software
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
openEuler
Ubuntu
mailman (Debian package)
mailman (Ubuntu package)
mailman
mailman-debugsource
mailman-debuginfo
How to mitigate CVE-2020-15011
mailman (Debian package) - update to 1:2.1.29-1+deb10u2
mailman (Ubuntu package) - update to 1:2.1.29-1ubuntu3.1
mailman - update to 2.1.29-8
mailman-debugsource - update to 2.1.29-8
mailman-debuginfo - update to 2.1.29-8