First published: Mon May 02 2005(Updated: )
The 55_options_traceback.dpatch patch for mailman 2.1.5 in Ubuntu 4.10 displays a different error message depending on whether the e-mail address is subscribed to a private list, which allows remote attackers to determine the list membership for a given e-mail address.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Mailman | =2.1.5 | |
Ubuntu Ubuntu Linux | =4.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2005-0080 is classified as medium.
To fix CVE-2005-0080, consider upgrading to a newer version of Mailman that addresses this vulnerability.
CVE-2005-0080 affects Mailman version 2.1.5 running on Ubuntu 4.10.
CVE-2005-0080 enables remote attackers to determine email list membership based on error messages.
There is no official workaround for CVE-2005-0080, so upgrading is the recommended method of mitigation.