Red Hat Bugzilla – Bug 1609090
CVE-2018-13796 mailman: Mishandled URLs in Utils.py:GetPathPieces() allows attackers to display arbitrary text on trusted sites
Last modified: 2018-08-02 12:01:19 EDT
Mailman before version 2.1.28 has a vulnerability in the Utils.py:GetPathPieces() function that allows an attacker to submit URLs with long listnames resulting in arbitrary text to be echoed in "No such list" error responses. This can be used to make a potential victim think the phishing text comes from a trusted site. Upstream Bug: https://bugs.launchpad.net/mailman/+bug/1780874 Upstream Patch: https://launchpadlibrarian.net/379908276/patch.txt Reference: https://www.mail-archive.com/mailman-users@python.org/msg71003.html
Created mailman tracking bugs for this issue: Affects: fedora-all [bug 1609091]