CVE-2004-1177

Impact:
Important
Public Date:
2005-01-10
Bugzilla:
1617389: CVE-2004-1177 security flaw

The MITRE CVE dictionary describes this issue as:

Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.

Find out more about CVE-2004-1177 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue did not affect the versions of mailman shipped with Red Hat Enterprise Linux 2.1, 3, or 4. In addition, we believe this issue does not apply to the 2.0.x versions of mailman due to setting of STEALTH_MODE

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 3 (mailman) RHSA-2005:235 2005-03-21
Red Hat Enterprise Linux 4 (mailman) RHSA-2005:235 2005-03-21

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.