Debian: 'mailman' cross-site scripting vulnerability
Summary
Package : mailman
Problem type : cross-site scripting hole
Debian-specific: no
Barry A. Warsaw reported several cross-site scripting security holes
in Mailman, due to non-existent escaping of CGI variables.
These have been fixed upstream in version 2.0.8, and the relevant
patches have been backported to version 1.1-10 in Debian.
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
Debian GNU/Linux 2.2 alias potato
---------------------------------
Potato was released for alpha, arm, i386, m68k, powerpc and sparc.
Source archives:
MD5 checksum: a9ae9e389e13622a9dd8a70a6a57f2b7
MD5 checksum: 8c77bc3c07be39e8ced4d85882eedf21
MD5 checksum: 42d499f4e1de6959c50b20a4eb0f432a
Alpha architecture:
MD5 checksum: 67f8c3c723ec8797117d1fed29f41369
ARM architecture:
MD5 checksum: 80d1fbee3ae7bab5e73ce860b4d8da87
Intel IA-32 architecture:
MD5 checksum: 27c9d400360a99b39954f563f5d0ed43
...