Skip to navigation

Security Advisory mailman security update

Advisory: RHSA-2006:0204-10
Type: Security Advisory
Severity: Moderate
Issued on: 2006-03-07
Last updated on: 2006-03-07
Affected Products: Red Hat Desktop (v. 3)
Red Hat Desktop (v. 4)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux AS (v. 4)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux ES (v. 4)
Red Hat Enterprise Linux WS (v. 3)
Red Hat Enterprise Linux WS (v. 4)
CVEs (cve.mitre.org): CVE-2005-3573
CVE-2005-4153

Details

An updated mailman package that fixes two security issues is now available
for Red Hat Enterprise Linux 3 and 4.

This update has been rated as having moderate security impact by the Red
Hat Security Response Team.

Mailman is software to help manage email discussion lists.

A flaw in handling of UTF8 character encodings was found in Mailman. An
attacker could send a carefully crafted email message to a mailing list run
by Mailman which would cause that particular mailing list to stop working.
The Common Vulnerabilities and Exposures project assigned the name
CVE-2005-3573 to this issue.

A flaw in date handling was found in Mailman version 2.1.4 through 2.1.6.
An attacker could send a carefully crafted email message to a mailing list
run by Mailman which would cause the Mailman server to crash. (CVE-2005-4153).

Users of Mailman should upgrade to this updated package, which contains
backported patches to correct these issues.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

This update is available via Red Hat Network. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Desktop (v. 3)

SRPMS:
mailman-2.1.5.1-25.rhel3.4.src.rpm
File outdated by:  RHBA-2007:0464
    MD5: f5d4951a169f2eb068d437e4fe4d1947
 
IA-32:
mailman-2.1.5.1-25.rhel3.4.i386.rpm
File outdated by:  RHBA-2007:0464
    MD5: 8767889afcdb41a3cbefe407bf085b3a
 
x86_64:
mailman-2.1.5.1-25.rhel3.4.x86_64.rpm
File outdated by:  RHBA-2007:0464
    MD5: 47471490f7cc7957d3c4f29f7481b7af
 
Red Hat Desktop (v. 4)

SRPMS:
mailman-2.1.5.1-34.rhel4.2.src.rpm
File outdated by:  RHSA-2011:0307
    MD5: 20fe1484a0040b98539002ab2f8f9489
 
IA-32:
mailman-2.1.5.1-34.rhel4.2.i386.rpm
File outdated by:  RHSA-2011:0307
    MD5: 0b183f570eb0c283a10ea9acf0dad764
 
x86_64:
mailman-2.1.5.1-34.rhel4.2.x86_64.rpm
File outdated by:  RHSA-2011:0307
    MD5: 0285d44261be2928af368c9aaf2b0420
 
Red Hat Enterprise Linux AS (v. 3)

SRPMS:
mailman-2.1.5.1-25.rhel3.4.src.rpm
File outdated by:  RHBA-2007:0464
    MD5: f5d4951a169f2eb068d437e4fe4d1947
 
IA-32:
mailman-2.1.5.1-25.rhel3.4.i386.rpm
File outdated by:  RHBA-2007:0464
    MD5: 8767889afcdb41a3cbefe407bf085b3a
 
IA-64:
mailman-2.1.5.1-25.rhel3.4.ia64.rpm
File outdated by:  RHBA-2007:0464
    MD5: 56b425bcd2dc95a3badac65f0120469d
 
PPC:
mailman-2.1.5.1-25.rhel3.4.ppc.rpm
File outdated by:  RHBA-2007:0464
    MD5: fd1e7c45fbd57cacabd7d150600208b2
 
s390:
mailman-2.1.5.1-25.rhel3.4.s390.rpm
File outdated by:  RHBA-2007:0464
    MD5: a76d66a94e7810d76b3587e250eb062d
 
s390x:
mailman-2.1.5.1-25.rhel3.4.s390x.rpm
File outdated by:  RHBA-2007:0464
    MD5: dc032425981d2106464c66073097ecbd
 
x86_64:
mailman-2.1.5.1-25.rhel3.4.x86_64.rpm
File outdated by:  RHBA-2007:0464
    MD5: 47471490f7cc7957d3c4f29f7481b7af
 
Red Hat Enterprise Linux AS (v. 4)

SRPMS:
mailman-2.1.5.1-34.rhel4.2.src.rpm
File outdated by:  RHSA-2011:0307
    MD5: 20fe1484a0040b98539002ab2f8f9489
 
IA-32:
mailman-2.1.5.1-34.rhel4.2.i386.rpm
File outdated by:  RHSA-2011:0307
    MD5: 0b183f570eb0c283a10ea9acf0dad764
 
IA-64:
mailman-2.1.5.1-34.rhel4.2.ia64.rpm
File outdated by:  RHSA-2011:0307
    MD5: c03eb2c91fd43e6ca55feff9927818b5
 
PPC:
mailman-2.1.5.1-34.rhel4.2.ppc.rpm
File outdated by:  RHSA-2011:0307
    MD5: f7c2d9411c5e52dbb27b5a92690ff59a
 
s390:
mailman-2.1.5.1-34.rhel4.2.s390.rpm
File outdated by:  RHSA-2011:0307
    MD5: fd31054f7e6dc8ce966fac7fc204340d
 
s390x:
mailman-2.1.5.1-34.rhel4.2.s390x.rpm
File outdated by:  RHSA-2011:0307
    MD5: d4489734eac372549ec927fff9db3d40
 
x86_64:
mailman-2.1.5.1-34.rhel4.2.x86_64.rpm
File outdated by:  RHSA-2011:0307
    MD5: 0285d44261be2928af368c9aaf2b0420
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
mailman-2.1.5.1-25.rhel3.4.src.rpm
File outdated by:  RHBA-2007:0464
    MD5: f5d4951a169f2eb068d437e4fe4d1947
 
IA-32:
mailman-2.1.5.1-25.rhel3.4.i386.rpm
File outdated by:  RHBA-2007:0464
    MD5: 8767889afcdb41a3cbefe407bf085b3a
 
IA-64:
mailman-2.1.5.1-25.rhel3.4.ia64.rpm
File outdated by:  RHBA-2007:0464
    MD5: 56b425bcd2dc95a3badac65f0120469d
 
x86_64:
mailman-2.1.5.1-25.rhel3.4.x86_64.rpm
File outdated by:  RHBA-2007:0464
    MD5: 47471490f7cc7957d3c4f29f7481b7af
 
Red Hat Enterprise Linux ES (v. 4)

SRPMS:
mailman-2.1.5.1-34.rhel4.2.src.rpm
File outdated by:  RHSA-2011:0307
    MD5: 20fe1484a0040b98539002ab2f8f9489
 
IA-32:
mailman-2.1.5.1-34.rhel4.2.i386.rpm
File outdated by:  RHSA-2011:0307
    MD5: 0b183f570eb0c283a10ea9acf0dad764
 
IA-64:
mailman-2.1.5.1-34.rhel4.2.ia64.rpm
File outdated by:  RHSA-2011:0307
    MD5: c03eb2c91fd43e6ca55feff9927818b5
 
x86_64:
mailman-2.1.5.1-34.rhel4.2.x86_64.rpm
File outdated by:  RHSA-2011:0307
    MD5: 0285d44261be2928af368c9aaf2b0420
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
mailman-2.1.5.1-25.rhel3.4.src.rpm
File outdated by:  RHBA-2007:0464
    MD5: f5d4951a169f2eb068d437e4fe4d1947
 
IA-32:
mailman-2.1.5.1-25.rhel3.4.i386.rpm
File outdated by:  RHBA-2007:0464
    MD5: 8767889afcdb41a3cbefe407bf085b3a
 
IA-64:
mailman-2.1.5.1-25.rhel3.4.ia64.rpm
File outdated by:  RHBA-2007:0464
    MD5: 56b425bcd2dc95a3badac65f0120469d
 
x86_64:
mailman-2.1.5.1-25.rhel3.4.x86_64.rpm
File outdated by:  RHBA-2007:0464
    MD5: 47471490f7cc7957d3c4f29f7481b7af
 
Red Hat Enterprise Linux WS (v. 4)

SRPMS:
mailman-2.1.5.1-34.rhel4.2.src.rpm
File outdated by:  RHSA-2011:0307
    MD5: 20fe1484a0040b98539002ab2f8f9489
 
IA-32:
mailman-2.1.5.1-34.rhel4.2.i386.rpm
File outdated by:  RHSA-2011:0307
    MD5: 0b183f570eb0c283a10ea9acf0dad764
 
IA-64:
mailman-2.1.5.1-34.rhel4.2.ia64.rpm
File outdated by:  RHSA-2011:0307
    MD5: c03eb2c91fd43e6ca55feff9927818b5
 
x86_64:
mailman-2.1.5.1-34.rhel4.2.x86_64.rpm
File outdated by:  RHSA-2011:0307
    MD5: 0285d44261be2928af368c9aaf2b0420
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

173139 - CVE-2005-3573 Mailman Denial of Service
176089 - CVE-2005-4153 Mailman DOS


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/