CVE-2015-2775
13.04.2015, 14:59
Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name.
| Vendor | Product | Version |
|---|---|---|
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 14.10 |
| debian | debian_linux | 7.0 |
| redhat | enterprise_linux | 7.0 |
| gnu | mailman | 𝑥 ≤ 2.1.19 |
𝑥
= Vulnerable software versions
Ubuntu Releases
References