Nessus Plugin #12253

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

Mailman Password Retrieval

Family:
Misc.
Category:
infos
Copyright:
This script is Copyright (C) 2004-2005 George A. Theall
Summary:
Checks for Mailman Password Retrieval Vulnerability
Version:
$Revision: 1.8 $
Cve_id:
CAN-2004-0412
Bugtraq_id:
10412
Xrefs:
OSVDB:6422, CLSA:CLSA-2004:842, FLSA:FEDORA-2004-1734, GLSA:GLSA-200406-04, MDKSA:MDKSA-2004:051
Description:

The target is running version of the Mailman mailing list software that
allows a list subscriber to retrieve the mailman password of any other
subscriber by means of a specially crafted mail message to the server.
That is, a message sent to $listname-request@$target containing the
lines :

password address=$victim
password address=$subscriber

will return the password of both $victim and $subscriber for the list
$listname@$target.

***** Nessus has determined the vulnerability exists on the target
***** simply by looking at the version number of Mailman installed
***** there.

Solution : Upgrade to Mailman version 2.1.5 or newer.
Risk factor : Medium
Generiert am 27.04.2005 um 18:49:54 Uhr.