CVE-2004-1143: High severity gnu mailman vulnerability
Published Dec 31, 2004
·Updated
The password generation in mailman before 2.1.5 generates only 5 million unique passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.
Affected Software
25 affected components
GNU Mailman=2.0.5
GNU Mailman=2.0.1
GNU Mailman=2.1.3
GNU Mailman=2.0.11
GNU Mailman=2.0.6
GNU Mailman=2.0-beta3
GNU Mailman=1.1
GNU Mailman=2.0-beta5
GNU Mailman=2.0.12
GNU Mailman=2.0
GNU Mailman=2.0-beta4
GNU Mailman=2.1.2
GNU Mailman=2.0.9
GNU Mailman=2.0.3
GNU Mailman=2.0.13
GNU Mailman=2.0.4
GNU Mailman=2.1
GNU Mailman=2.1b1
GNU Mailman=2.1.1
GNU Mailman=1.0
GNU Mailman=2.0.8
GNU Mailman=2.1.4
GNU Mailman=2.0.10
GNU Mailman=2.0.2
GNU Mailman=2.0.7
Remediation
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Jan 19, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1143?
CVE-2004-1143 is considered a high severity vulnerability due to the potential for remote attackers to guess passwords via a brute force attack.
2
How do I fix CVE-2004-1143?
Upgrading Mailman to version 2.1.5 or later patches the vulnerability related to password generation.
3
What versions of Mailman are affected by CVE-2004-1143?
CVE-2004-1143 affects Mailman versions 1.0 through 2.1.4.
4
What impact does CVE-2004-1143 have on password security?
CVE-2004-1143 reduces password security, allowing attackers to potentially brute force passwords due to a limited set of unique passwords.
5
Is there a known exploit for CVE-2004-1143?
Yes, CVE-2004-1143 can be exploited by attackers who utilize brute force techniques to guess passwords.