cbcvebase.
CVE-2015-2775
published 2015-04-13

CVE-2015-2775: Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot…

high7.6CVSS 3.1
AVNACHAuNCCICAC
Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name.

Affected

7 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
gnumailman<= 2.1.19
gnumailman>= 0 < 1:2.1.16-2ubuntu0.11:2.1.16-2ubuntu0.1
redhatenterprise_linux

CVSS provenance

nvd7.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
osv7.6HIGH