Ubuntu Security Notice USN-3118-1

Discussion in 'News Aggregator' started by Packet Storm, 2 Nov 2016.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 3118-1 - It was discovered that the Mailman administrative web interface did not protect against cross-site request forgery attacks. If an authenticated user were tricked into visiting a malicious website while logged into Mailman, a remote attacker could perform administrative actions. This issue only affected Ubuntu 12.04 LTS. Nishant Agarwala discovered that the Mailman user options page did not protect against cross-site request forgery attacks. If an authenticated user were tricked into visiting a malicious website while logged into Mailman, a remote attacker could modify user options. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...