First published: Tue Jun 18 2002(Updated: )
Pipermail in Mailman stores private mail messages with predictable filenames in a world-executable directory, which allows local users to read private mailing list archives.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mailman |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0389 is considered to be of medium severity due to the potential for local users to access private mailing list archives.
To fix CVE-2002-0389, ensure that private mail messages are stored in a secure directory that is not world-executable.
CVE-2002-0389 affects all versions of Mailman prior to the fix that secures private mail message storage.
CVE-2002-0389 is a local information disclosure vulnerability that allows unauthorized access to private mailing lists.
CVE-2002-0389 can impact any organization using Mailman that has configured private mailing lists, potentially exposing sensitive information to local users.