Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.52809
Category:Fedora Local Security Checks
Title:Fedora Legacy Security Advisory FLSA-2004:1734
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory FLSA-2004:1734.

Mailman is software to help manage email discussion lists, much like
Majordomo and Smartmail. Unlike most similar products, Mailman gives each
mailing list a webpage, and allows users to subscribe, unsubscribe, etc.
over the Web. Even the list manager can administer his or her list
entirely from the Web. Mailman also integrates most things people want to
do with mailing lists, including archiving, mail <-> news gateways, and so
on.

A flaw in Mailman 2.1.* allows a remote attacker to retrieve the mailman
password of any subscriber by sending a carefully crafted email request to
the mailman server.

A simple patch is available and is fixed upstream in Mailman 2.1.5.

All users are advised to upgrade to these updated packages, which contain a
backported fix and are not vulnerable to this issue.

Fedora Legacy would like to thank Marc Deslauriers for reporting this
issue.

Affected platforms:
Redhat 7.3

Solution:
https://secure1.securityspace.com/smysecure/catid.html?in=FLSA-2004:1734
http://mail.python.org/pipermail/mailman-announce/2004-May/000072.html

Risk factor : Medium

CVSS Score:
5.0

Cross-Ref: BugTraq ID: 10412
Common Vulnerability Exposure (CVE) ID: CVE-2004-0412
http://www.securityfocus.com/bid/10412
Conectiva Linux advisory: CLA-2004:842
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000842
http://marc.info/?l=bugtraq&m=109034869927955&w=2
http://security.gentoo.org/glsa/glsa-200406-04.xml
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:051
http://mail.python.org/pipermail/mailman-announce/2004-May/000072.html
http://secunia.com/advisories/11701
XForce ISS Database: mailman-obtain-password(16256)
https://exchange.xforce.ibmcloud.com/vulnerabilities/16256
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.