CVE-2002-0389: Low severity gnu mailman vulnerability
Pipermail in Mailman stores private mail messages with predictable filenames in a world-executable directory, which allows local users to read private mailing list archives.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0389?
CVE-2002-0389 is considered to be of medium severity due to the potential for local users to access private mailing list archives.
How do I fix CVE-2002-0389?
To fix CVE-2002-0389, ensure that private mail messages are stored in a secure directory that is not world-executable.
Which versions of Mailman are affected by CVE-2002-0389?
CVE-2002-0389 affects all versions of Mailman prior to the fix that secures private mail message storage.
What type of vulnerability is CVE-2002-0389?
CVE-2002-0389 is a local information disclosure vulnerability that allows unauthorized access to private mailing lists.
Who can be impacted by CVE-2002-0389?
CVE-2002-0389 can impact any organization using Mailman that has configured private mailing lists, potentially exposing sensitive information to local users.