CVE-2004-0412: Infoleak
Published Jun 3, 2004
·Updated
Mailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server.
Affected Software
7 affected componentsFixes available
pip/mailman<2.1.5
2.1.5
GNU Mailman=2.1
GNU Mailman=2.1.1
GNU Mailman=2.1.2
GNU Mailman=2.1.3
GNU Mailman=2.1.4
GNU Mailman=2.1b1
Remediation
Patch Available
Event History
Jun 3, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Apr 29, 2022
Advisory Published
02:57 AM
Frequently Asked Questions
1
What is the severity of CVE-2004-0412?
CVE-2004-0412 is classified as a moderate severity vulnerability that allows remote attackers to obtain user passwords.
2
How do I fix CVE-2004-0412?
To fix CVE-2004-0412, you should upgrade your Mailman installation to version 2.1.5 or later.
3
What versions of Mailman are affected by CVE-2004-0412?
CVE-2004-0412 affects Mailman versions 2.1.4 and earlier.
4
Can CVE-2004-0412 be exploited remotely?
Yes, CVE-2004-0412 can be exploited remotely through a crafted email request.
5
What type of information can be compromised due to CVE-2004-0412?
CVE-2004-0412 can lead to the exposure of user passwords.