From b2a8ab50ca10ff83839cd876f7f9a6495c33293c Mon Sep 17 00:00:00 2001 From: bwarsaw <> Date: Thu, 10 Feb 2005 14:10:10 +0000 Subject: Add information regarding CAN-2005-0202 vulnerability, with patches and recommendations. Also include reference to a new email address folks can use to contact the Mailman security response team. --- admin/www/security.html | 197 ++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 197 insertions(+) create mode 100644 admin/www/security.html (limited to 'admin/www/security.html') diff --git a/admin/www/security.html b/admin/www/security.html new file mode 100644 index 00000000..4d7c40cb --- /dev/null +++ b/admin/www/security.html @@ -0,0 +1,197 @@ + + + + + + + + + +Mailman security issues + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ +
  
  
+

Mailman security issues

+ +The GNU Mailman developers take security very seriously. All Mailman security +concerns should be emailed to +mailman-security@python.org. This is +a closed list that reaches the core Mailman developers. + +

Known issues and fixes

+ +
    +
  • CAN-2005-0202 -- This is a very serious issue affecting +the Mailman 2.1 serious up to and including version 2.1.5. Mailman 2.1.6 is +not vulnerable. This issue can allow for the leakage of member passwords. + +

    The extent of your exposure to this vulnerability depends on factors such +as which version of Apache you are running and how you have it configured. We +do not currently know the exact combination that enables the hole, although we +currently believe that Apache 2.0 sites are not vulnerable and that that many +if not most Apache 1.3 sites are vulnerable. In any event, the safest +approach is to assume the worst and it is recommended that you apply +this Mailman patch as soon as possible. + +

    For additional piece of mind, it is +recommended that you regenerate your list member passwords using +the Mailman 2.1.6 reset_pw.py script. Put this file +in your Mailman installation's bin directory. After running the script, you +might also want to manually run the cron/mailpasswds script so that your users +will be informed of their new passwords. +

  • +
+ +
+ -- cgit v1.2.3