{"id":"MGASA-2016-0343","summary":"Updated mailman package fixes security vulnerability","details":"Cross-site request forgery (CSRF) vulnerability in the user options page in \nGNU Mailman 2.1.x before 2.1.23 allows remote attackers to hijack the \nauthentication of arbitrary users for requests that modify an option, as \ndemonstrated by gaining access to the credentials of a victim's account \n(CVE-2016-6893).\n","modified":"2026-04-16T06:24:49.341499622Z","published":"2016-10-18T18:43:39Z","upstream":["CVE-2016-6893"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2016-0343.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=19287"},{"type":"WEB","url":"https://www.debian.org/security/2016/dsa-3668"}],"affected":[{"package":{"name":"mailman","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/mailman?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.20-3.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0343.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}