CVE-2005-0202

Publication date 2 May 2005

Last updated 24 July 2024


Ubuntu priority

Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary files via ".../....///" sequences, which are not properly cleansed by regular expressions that are intended to remove "../" and "./" sequences.

Status

Package Ubuntu Release Status
mailman 7.04 feisty
Fixed 2.1.8-2ubuntu2
6.10 edgy
Fixed 2.1.8-2ubuntu2
6.06 LTS dapper
Fixed 2.1.5-9ubuntu4.1

References

Related Ubuntu Security Notices (USN)

    • USN-78-2
    • Fixed mailman packages for USN-78-1
    • 17 February 2005
    • USN-78-1
    • Mailman vulnerability
    • 10 February 2005

Other references