A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site.

Bug #1913241 reported by Abderrahmane Sahnoun
2
Affects Status Importance Assigned to Milestone
GNU Mailman
New
Undecided
Abderrahmane Sahnoun

Bug Description

A URL with a very long text listname such as
https://homewalkers.net/mailman/roster/This_is_a_long_string_with_some_phishing_text
will echo the text in the "No such list" error response. This can be used to make a potential victim think the phishing text comes from a trusted site.

This issue was discovered by Abderrahmane Sahnoun <email address hidden>.
same as CVE-2018-13796

CVE References

Changed in mailman:
assignee: nobody → Abderrahmane Sahnoun (xvirusdz)
description: updated
description: updated
Changed in mailman:
assignee: Abderrahmane Sahnoun (xvirusdz) → nobody
description: updated
Changed in mailman:
assignee: nobody → Abderrahmane Sahnoun (xvirusdz)
Mark Sapiro (msapiro)
information type: Private Security → Public
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.