---
title: "CVE-2009-4896\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2009-4896?format=md
keywords: index, follow
---

# CVE-2009-4896

Publication date 2 August 2010

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Multiple directory traversal vulnerabilities in the mlmmj-php-admin web
interface for Mailing List Managing Made Joyful (mlmmj) 1.2.15 through
1.2.17 allow remote authenticated users to overwrite, create, or delete
arbitrary files, or determine the existence of arbitrary directories, via a
.. (dot dot) in a list name in a (1) edit or (2) save action.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| mlmmj | 13.10 saucy | Not affected |
| 13.04 raring | Not affected |
| 12.10 quantal | Not affected |
| 12.04 LTS precise | Not affected |
| 11.10 oneiric | Not affected |
| 11.04 natty | Not affected |
| 10.10 maverick | Not affected |
| 10.04 LTS lucid | Ignored end of life |
| 9.10 karmic | Fixed 1.2.15-1.1+lenny1build0.9.10.1 |
| 9.04 jaunty | Fixed 1.2.15-1.1+lenny1build0.9.04.1 |
| 8.04 LTS hardy | Ignored end of life |
| 6.06 LTS dapper | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4896)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2009-4896)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2009-4896)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2009-4896)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2009-4896>
