LWN.net Logo

smartlist: wrong input processing

Package(s):smartlist CVE #(s):CAN-2005-0157
Created:May 3, 2005 Updated:May 3, 2005
Description: Jeroen van Wolffelaar noticed that the confirm add-on of SmartList, the listmanager used on lists.debian.org, which is used on that host as well, could be tricked to subscribe arbitrary addresses to the lists.
Alerts:
Debian DSA-720-1 2005-05-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds