CVE-2005-0080: Medium severity GNU Mailman vulnerability
Published Jan 19, 2005
·Updated
The 55optionstraceback.dpatch patch for mailman 2.1.5 in Ubuntu 4.10 displays a different error message depending on whether the e-mail address is subscribed to a private list, which allows remote attackers to determine the list membership for a given e-mail address.
Affected Software
2 affected components
GNU Mailman=2.1.5
Ubuntu Ubuntu Linux=4.10
Event History
Jan 19, 2005
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0080?
The severity of CVE-2005-0080 is classified as medium.
2
How do I fix CVE-2005-0080?
To fix CVE-2005-0080, consider upgrading to a newer version of Mailman that addresses this vulnerability.
3
What software is affected by CVE-2005-0080?
CVE-2005-0080 affects Mailman version 2.1.5 running on Ubuntu 4.10.
4
What kind of attack does CVE-2005-0080 enable?
CVE-2005-0080 enables remote attackers to determine email list membership based on error messages.
5
Is there a known workaround for CVE-2005-0080?
There is no official workaround for CVE-2005-0080, so upgrading is the recommended method of mitigation.